|
222921
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_…
|
NVD-CWE-noinfo
|
CVE-2019-14441
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222922
|
3.3 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
|
NVD-CWE-noinfo
|
CVE-2019-14391
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222923
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
|
CWE-79
Cross-site Scripting
|
CVE-2019-14390
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222924
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
|
NVD-CWE-noinfo
|
CVE-2019-14389
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222925
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
|
NVD-CWE-noinfo
|
CVE-2019-14388
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222926
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
|
CWE-79
Cross-site Scripting
|
CVE-2019-14387
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222927
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
|
CWE-79
Cross-site Scripting
|
CVE-2019-14386
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222928
|
7.5 |
HIGH
Network
|
openmpt
|
libopenmpt
|
libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14381
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222929
|
6.5 |
MEDIUM
Network
|
custom_simple_rss_project
|
custom_simple_rss
|
A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings.
|
CWE-352
Origin Validation Error
|
CVE-2019-14327
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222930
|
9.8 |
CRITICAL
Network
|
matrixssl
|
matrixssl
|
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parse…
|
CWE-787 CWE-755
Out-of-bounds Write Improper Handling of Exceptional Conditions
|
CVE-2019-14431
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|