|
223431
|
5.5 |
MEDIUM
Local
|
imagemagick opensuse
|
imagemagick leap
|
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-13133
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223432
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" …
|
CWE-77
Command Injection
|
CVE-2019-13024
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223433
|
9.8 |
CRITICAL
Network
|
supermicro
|
superdoctor_5
|
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13131
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223434
|
7.5 |
HIGH
Network
|
motorola
|
cx2l_mwr04l_firmware
|
On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handli…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13129
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223435
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway …
|
CWE-78
OS Command
|
CVE-2019-13128
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223436
|
6.1 |
MEDIUM
Network
|
draw jgraph
|
draw.io_diagrams mxgraph
|
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field lea…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2019-13127
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223437
|
7.8 |
HIGH
Local
|
tencent
|
habomalhunter
|
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2019-13125
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223438
|
5.3 |
MEDIUM
Network
|
xmlsoft opensuse netapp oracle fedoraproject canonical apple
|
libxslt leap cloud_backup steelstore_cloud_integrated_storage oncommand_workflow_automation oncommand_insight ontap_select_deploy_administration_utility clustered_data_ontap e…
|
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, …
|
CWE-843
Type Confusion
|
CVE-2019-13118
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223439
|
5.3 |
MEDIUM
Network
|
xmlsoft debian canonical fedoraproject opensuse oracle
|
libxslt debian_linux ubuntu_linux fedora leap openjdk
|
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte o…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-13117
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223440
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject debian canonical
|
exiv2 fedora debian_linux ubuntu_linux
|
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13114
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|