|
223001
|
7.5 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a NULL pointer dereference and crash when getting a PDF object from a document, or parsing a certain por…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14208
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223002
|
7.5 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling the clone function due to an endless loop resulting from confusing relationships between a child an…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-14207
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223003
|
7.5 |
HIGH
Network
|
nevma
|
adaptive_images
|
An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to delete arbitrary files via the $REQUEST['adaptive-images-settings']…
|
CWE-22
Path Traversal
|
CVE-2019-14206
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223004
|
7.5 |
HIGH
Network
|
nevma
|
adaptive_images
|
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['…
|
CWE-22
Path Traversal
|
CVE-2019-14205
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223005
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security sever…
|
CWE-269
Improper Privilege Management
|
CVE-2019-13690
|
2024-11-21 13:25 |
2023-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223006
|
7.8 |
HIGH
Local
|
google
|
chrome
|
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Crit…
|
CWE-59
Link Following
|
CVE-2019-13689
|
2024-11-21 13:25 |
2023-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223007
|
7.4 |
HIGH
Network
|
google
|
chrome
|
Use after free in FileAPI in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chrome security severity: High)
|
CWE-416
Use After Free
|
CVE-2019-13768
|
2024-11-21 13:25 |
2023-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223008
|
6.5 |
MEDIUM
Adjacent
|
sierrawireless
|
mgos
|
Sierra Wireless MGOS before 3.15.2 and 4.x before 4.3 allows attackers to read log files via a Direct Request (aka Forced Browsing).
|
NVD-CWE-noinfo
|
CVE-2019-13988
|
2024-11-21 13:25 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223009
|
6.1 |
MEDIUM
Network
|
blinger
|
blinger
|
Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-in communication channel, such as Telegram, WhatsApp, Viber, Skype, Facebook, V…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13633
|
2024-11-21 13:25 |
2020-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223010
|
7.8 |
HIGH
Local
|
qualcomm
|
kamorta_firmware mdm9150_firmware mdm9205_firmware mdm9607_firmware mdm9650_firmware nicobar_firmware qcs404_firmware qcs405_firmware qcs605_firmware qcs610_firmware ren…
|
u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, S…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14056
|
2024-11-21 13:25 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|