|
222411
|
7.5 |
HIGH
Network
|
omg
|
dds_security
|
The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the capabilities of a participant (including capabilities inapplicable to the current…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-15135
|
2024-11-21 13:28 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222412
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network th…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-15134
|
2024-11-21 13:28 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222413
|
6.5 |
MEDIUM
Network
|
giflib_project canonical debian
|
giflib ubuntu_linux debian_linux
|
In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to z…
|
CWE-369
Divide By Zero
|
CVE-2019-15133
|
2024-11-21 13:28 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222414
|
5.3 |
MEDIUM
Network
|
zabbix debian
|
zabbix debian_linux
|
Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernames based on the variability of server responses (e.g., the "Login name or passw…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-15132
|
2024-11-21 13:28 |
2019-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222415
|
6.1 |
MEDIUM
Network
|
sandhillsdev
|
easy_digital_downloads
|
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15116
|
2024-11-21 13:28 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222416
|
8.8 |
HIGH
Network
|
profilepress
|
loginwp
|
The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15115
|
2024-11-21 13:28 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222417
|
8.8 |
HIGH
Network
|
ncrafts
|
formcraft
|
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15114
|
2024-11-21 13:28 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222418
|
8.8 |
HIGH
Network
|
codeermeneer
|
companion_sitemap_generator
|
The companion-sitemap-generator plugin before 3.7.0 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15113
|
2024-11-21 13:28 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222419
|
5.4 |
MEDIUM
Network
|
kunena
|
kunena
|
The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15120
|
2024-11-21 13:28 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222420
|
5.5 |
MEDIUM
Local
|
nps_project
|
nps
|
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15119
|
2024-11-21 13:28 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|