|
224001
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13323
|
2024-11-21 13:24 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224002
|
9.8 |
CRITICAL
Network
|
compal
|
ch7465lg_firmware
|
Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containi…
|
CWE-78 CWE-669
OS Command Incorrect Resource Transfer Between Spheres
|
CVE-2019-13025
|
2024-11-21 13:24 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224003
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-13335
|
2024-11-21 13:24 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224004
|
7.5 |
HIGH
Network
|
butor
|
portal
|
Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers…
|
CWE-22
Path Traversal
|
CVE-2019-13343
|
2024-11-21 13:24 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224005
|
7.5 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 2 o…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13124
|
2024-11-21 13:24 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224006
|
7.5 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack memory because of Uncontrolled Recursion in the V8 JavaScript engine (issue 1 o…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13123
|
2024-11-21 13:24 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224007
|
5.9 |
MEDIUM
Network
|
sandisk westerndigital
|
ssd_dashboard
|
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download …
|
NVD-CWE-noinfo
|
CVE-2019-13467
|
2024-11-21 13:24 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224008
|
7.5 |
HIGH
Network
|
sandisk westerndigital
|
ssd_dashboard
|
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An applica…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-13466
|
2024-11-21 13:24 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224009
|
6.5 |
MEDIUM
Network
|
phpbb
|
phpbb
|
phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-13376
|
2024-11-21 13:24 |
2019-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224010
|
7.8 |
HIGH
Local
|
totaldefense
|
anti-virus
|
In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTE…
|
CWE-426
Untrusted Search Path
|
CVE-2019-13357
|
2024-11-21 13:24 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|