|
223071
|
8.8 |
HIGH
Network
|
mirumee
|
saleor
|
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
|
CWE-352
Origin Validation Error
|
CVE-2019-13594
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223072
|
5.5 |
MEDIUM
Local
|
sound_exchange_project
|
sound_exchange
|
An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro th…
|
CWE-190 CWE-476
Integer Overflow or Wraparound NULL Pointer Dereference
|
CVE-2019-13590
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223073
|
9.8 |
CRITICAL
Network
|
anjlab
|
paranoid2
|
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2019-13589
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223074
|
8.8 |
HIGH
Network
|
zoom
|
zoom
|
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zo…
|
CWE-78
OS Command
|
CVE-2019-13567
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223075
|
7.8 |
HIGH
Local
|
castlerock
|
simple_network_management_protocol_console
|
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long variable string in a Map Objects text file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13494
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223076
|
7.8 |
HIGH
Local
|
minimagick_project debian
|
minimagick debian_linux
|
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts …
|
CWE-78
OS Command
|
CVE-2019-13574
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223077
|
6.1 |
MEDIUM
Network
|
pingidentity
|
agentless_integration_kit
|
XSS exists in Ping Identity Agentless Integration Kit before 1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13564
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223078
|
8.8 |
HIGH
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
|
CWE-352
Origin Validation Error
|
CVE-2019-13563
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223079
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr parameter, the /www/ping6_response.cgi ping6_ipaddr parameter, and the /www/apply_s…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13562
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223080
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-655_firmware
|
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
|
CWE-78
OS Command
|
CVE-2019-13561
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|