|
224261
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway …
|
CWE-78
OS Command
|
CVE-2019-13128
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224262
|
6.1 |
MEDIUM
Network
|
draw jgraph
|
draw.io_diagrams mxgraph
|
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field lea…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2019-13127
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224263
|
7.8 |
HIGH
Local
|
tencent
|
habomalhunter
|
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2019-13125
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224264
|
5.3 |
MEDIUM
Network
|
xmlsoft opensuse netapp oracle fedoraproject canonical apple
|
libxslt leap cloud_backup steelstore_cloud_integrated_storage oncommand_workflow_automation oncommand_insight ontap_select_deploy_administration_utility clustered_data_ontap e…
|
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, …
|
CWE-843
Type Confusion
|
CVE-2019-13118
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224265
|
5.3 |
MEDIUM
Network
|
xmlsoft debian canonical fedoraproject opensuse oracle
|
libxslt debian_linux ubuntu_linux fedora leap openjdk
|
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte o…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-13117
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224266
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject debian canonical
|
exiv2 fedora debian_linux ubuntu_linux
|
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13114
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224267
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject canonical
|
exiv2 fedora ubuntu_linux
|
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
|
CWE-617
Reachable Assertion
|
CVE-2019-13113
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224268
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject canonical debian
|
exiv2 fedora ubuntu_linux debian_linux
|
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-13112
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224269
|
5.5 |
MEDIUM
Local
|
exiv2 fedoraproject
|
exiv2 fedora
|
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP imag…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13111
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224270
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject canonical debian
|
exiv2 fedora ubuntu_linux debian_linux
|
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2019-13110
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|