|
222681
|
5.3 |
MEDIUM
Network
|
woocommerce
|
payu_india_payment_gateway
|
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for l…
|
CWE-20
Improper Input Validation
|
CVE-2019-14978
|
2024-11-21 13:27 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222682
|
5.3 |
MEDIUM
Network
|
woocommerce
|
paypal_checkout_payment_gateway
|
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purcha…
|
CWE-20
Improper Input Validation
|
CVE-2019-14979
|
2024-11-21 13:27 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222683
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14970
|
2024-11-21 13:27 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222684
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
|
CWE-416
Use After Free
|
CVE-2019-14778
|
2024-11-21 13:27 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222685
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
|
CWE-416
Use After Free
|
CVE-2019-14777
|
2024-11-21 13:27 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222686
|
7.8 |
HIGH
Local
|
videolan debian
|
vlc_media_player debian_linux
|
A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14776
|
2024-11-21 13:27 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222687
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-14943
|
2024-11-21 13:27 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222688
|
4.7 |
MEDIUM
Local
|
comodo
|
antivirus
|
A use-after-free flaw in the sandbox container implemented in cmdguard.sys in Comodo Antivirus 12.0.0.6870 can be triggered due to a race condition when handling IRP_MJ_CLEANUP requests in the minifi…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-14694
|
2024-11-21 13:27 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222689
|
6.5 |
MEDIUM
Network
|
mikrotik
|
routeros
|
MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to re…
|
CWE-22
Path Traversal
|
CVE-2019-15055
|
2024-11-21 13:27 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222690
|
4.3 |
MEDIUM
Network
|
atlassian
|
universal_plugin_manager
|
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers t…
|
CWE-352
Origin Validation Error
|
CVE-2019-14999
|
2024-11-21 13:27 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|