|
222531
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15047
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222532
|
6.1 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14974
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222533
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
|
CWE-287
Improper Authentication
|
CVE-2019-15046
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222534
|
9.8 |
CRITICAL
Network
|
ninjaforms
|
ninjaforms
|
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
|
CWE-89
SQL Injection
|
CVE-2019-15025
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222535
|
7.1 |
HIGH
Local
|
artifex
|
mupdf
|
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14975
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222536
|
6.5 |
MEDIUM
Network
|
libtiff debian fedoraproject opensuse
|
libtiff debian_linux fedora leap
|
_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards.…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14973
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222537
|
9.8 |
CRITICAL
Network
|
mediatek
|
mt8163_firmware mt6625_firmware mt6577_firmware
|
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filen…
|
CWE-78
OS Command
|
CVE-2019-15027
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222538
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
|
NVD-CWE-noinfo
|
CVE-2019-15028
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222539
|
9.8 |
CRITICAL
Network
|
golang debian
|
go debian_linux
|
net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appear…
|
NVD-CWE-noinfo
|
CVE-2019-14809
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222540
|
8.1 |
HIGH
Network
|
eq-3
|
homematic_ccu2_firmware homematic_ccu3_firmware
|
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Br…
|
NVD-CWE-noinfo
|
CVE-2019-14986
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|