|
224071
|
5.5 |
MEDIUM
Local
|
stb_vorbis_project debian
|
stb_vorbis debian_linux
|
Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file.
|
CWE-369
Divide By Zero
|
CVE-2019-13218
|
2024-11-21 13:24 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224072
|
7.8 |
HIGH
Local
|
stb_vorbis_project debian
|
stb_vorbis debian_linux
|
A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13217
|
2024-11-21 13:24 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224073
|
8.2 |
HIGH
Network
|
mediola
|
neo_server
|
eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to start or stop the Node.js process, resulting in the ability to obtain mediola conf…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2019-13030
|
2024-11-21 13:24 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224074
|
6.5 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s…
|
NVD-CWE-Other
|
CVE-2019-13416
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224075
|
6.5 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see.
|
NVD-CWE-Other
|
CVE-2019-13415
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224076
|
5.9 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-13420
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224077
|
7.5 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.
|
CWE-200
Information Exposure
|
CVE-2019-13419
|
2024-11-21 13:24 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224078
|
7.5 |
HIGH
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.
|
CWE-129
Improper Validation of Array Index
|
CVE-2019-13418
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224079
|
5.3 |
MEDIUM
Network
|
search-guard
|
search_guard
|
Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activ…
|
CWE-200
Information Exposure
|
CVE-2019-13417
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224080
|
9.1 |
CRITICAL
Network
|
lansweeper
|
lansweeper
|
Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-13462
|
2024-11-21 13:24 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|