|
210981
|
5.9 |
MEDIUM
Network
|
mozilla
|
thunderbird firefox_esr firefox
|
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vu…
|
CWE-843
Type Confusion
|
CVE-2019-9816
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210982
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9814
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210983
|
8.3 |
HIGH
Network
|
mozilla debian novell opensuse
|
firefox firefox_esr thunderbird debian_linux suse_package_hub_for_suse_linux_enterprise leap
|
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This v…
|
CWE-74
Injection
|
CVE-2019-9811
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210984
|
9.8 |
CRITICAL
Network
|
mozilla
|
thunderbird firefox_esr firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we pres…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9800
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210985
|
6.5 |
MEDIUM
Network
|
freedesktop debian fedoraproject redhat
|
poppler debian_linux fedora enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory ch…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9959
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210986
|
8.1 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-9815
|
2024-11-21 13:52 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210987
|
4.3 |
MEDIUM
Network
|
libreoffice canonical fedoraproject debian opensuse
|
libreoffice ubuntu_linux fedora debian_linux leap
|
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who w…
|
NVD-CWE-noinfo
|
CVE-2019-9849
|
2024-11-21 13:52 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210988
|
9.8 |
CRITICAL
Network
|
libreoffice canonical fedoraproject debian opensuse
|
libreoffice ubuntu_linux fedora debian_linux leap
|
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLo…
|
CWE-94
Code Injection
|
CVE-2019-9848
|
2024-11-21 13:52 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210989
|
3.9 |
LOW
Physics
|
norton
|
password_manager
|
Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may allow an attacker to disguise their origin IP address in order to obfuscate the s…
|
NVD-CWE-noinfo
|
CVE-2019-9700
|
2024-11-21 13:52 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210990
|
7.5 |
HIGH
Network
|
eclass
|
eclass_ip
|
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.
|
CWE-22
Path Traversal
|
CVE-2019-9886
|
2024-11-21 13:52 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|