|
222711
|
6.8 |
MEDIUM
Network
|
atlassian
|
html_include_and_replace_macro
|
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15053
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222712
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15050
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222713
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15049
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222714
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15048
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222715
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15047
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222716
|
6.1 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14974
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222717
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
|
CWE-287
Improper Authentication
|
CVE-2019-15046
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222718
|
9.8 |
CRITICAL
Network
|
ninjaforms
|
ninjaforms
|
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
|
CWE-89
SQL Injection
|
CVE-2019-15025
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222719
|
7.1 |
HIGH
Local
|
artifex
|
mupdf
|
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14975
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222720
|
6.5 |
MEDIUM
Network
|
libtiff debian fedoraproject opensuse
|
libtiff debian_linux fedora leap
|
_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards.…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14973
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|