|
222941
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-14372
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222942
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-14371
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222943
|
6.5 |
MEDIUM
Network
|
exiv2 debian
|
exiv2 debian_linux
|
In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14370
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222944
|
6.5 |
MEDIUM
Network
|
exiv2 debian
|
exiv2 debian_linux
|
Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14369
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222945
|
7.8 |
HIGH
Local
|
exiv2
|
exiv2
|
Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14368
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222946
|
6.1 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using th…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14364
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222947
|
9.8 |
CRITICAL
Network
|
netgear
|
wndr3400v3_firmware
|
A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1.0.63 allows an attacker to remotely execute arbitrary code via a crafted UPnP …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14363
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222948
|
5.4 |
MEDIUM
Network
|
openbravo
|
openbravo_erp
|
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNew…
|
CWE-22
Path Traversal
|
CVE-2019-14362
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222949
|
7.8 |
HIGH
Local
|
joget
|
worfklow
|
In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-14352
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222950
|
8.8 |
HIGH
Network
|
espocrm
|
espocrm
|
EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user password hash by 1 symbol at a time using specially crafted api/v1/User?filter…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-14351
|
2024-11-21 13:26 |
2019-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|