|
222291
|
7.8 |
HIGH
Local
|
pam-python_project debian canonical
|
pam-python debian_linux ubuntu_linux
|
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
|
NVD-CWE-noinfo
|
CVE-2019-16729
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222292
|
6.1 |
MEDIUM
Network
|
cure53 debian
|
dompurify debian_linux
|
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16728
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222293
|
4.3 |
MEDIUM
Network
|
cacti
|
cacti
|
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-16723
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222294
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
|
NVD-CWE-noinfo
|
CVE-2019-16722
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222295
|
6.5 |
MEDIUM
Network
|
5none
|
nonecms
|
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
|
CWE-352
Origin Validation Error
|
CVE-2019-16721
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222296
|
7.5 |
HIGH
Network
|
zzzcms
|
zzzphp
|
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16720
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222297
|
6.5 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-16719
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222298
|
7.8 |
HIGH
Local
|
radare
|
radare2
|
In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the …
|
CWE-78
OS Command
|
CVE-2019-16718
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222299
|
7.5 |
HIGH
Network
|
linux canonical f5
|
linux_kernel ubuntu_linux traffix_signaling_delivery_controller
|
In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
|
CWE-909
Missing Initialization of Resource
|
CVE-2019-16714
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222300
|
6.5 |
MEDIUM
Network
|
imagemagick canonical opensuse debian
|
imagemagick ubuntu_linux leap debian_linux
|
ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-16713
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|