|
222841
|
7.5 |
HIGH
Network
|
djangoproject opensuse
|
django leap
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-14235
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222842
|
7.5 |
HIGH
Network
|
djangoproject opensuse
|
django leap
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremel…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-14233
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222843
|
7.5 |
HIGH
Network
|
djangoproject opensuse
|
django leap
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-14232
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222844
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
|
CWE-89
SQL Injection
|
CVE-2019-14529
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222845
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14528
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222846
|
7.8 |
HIGH
Local
|
schismtracker opensuse
|
schism_tracker leap backports
|
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14524
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222847
|
7.8 |
HIGH
Local
|
schismtracker
|
schism_tracker
|
An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_load_song in the Amiga Oktalyzer parser in fmt/okt.c.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2019-14523
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222848
|
6.1 |
MEDIUM
Network
|
editor.md_project
|
editor.md
|
pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14517
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222849
|
7.5 |
HIGH
Network
|
thekelleys debian
|
dnsmasq debian_linux
|
Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a differ…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14513
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222850
|
8.0 |
HIGH
Adjacent
|
al-enterprise
|
8008_firmware
|
On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change …
|
CWE-78
OS Command
|
CVE-2019-14260
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|