|
222651
|
8.8 |
HIGH
Network
|
hallme
|
woocommerce_address_book
|
The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
|
CWE-352
Origin Validation Error
|
CVE-2019-15770
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222652
|
8.8 |
HIGH
Network
|
haktansuren
|
handl_utm_grabber
|
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
|
CWE-352
Origin Validation Error
|
CVE-2019-15769
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222653
|
7.8 |
HIGH
Local
|
gnu
|
chess
|
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15767
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222654
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15759
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222655
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-se…
|
CWE-617
Reachable Assertion
|
CVE-2019-15758
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222656
|
6.5 |
MEDIUM
Network
|
libmirage_project
|
libmirage
|
libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15757
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222657
|
7.8 |
HIGH
Local
|
docker apache
|
docker geode
|
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15752
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222658
|
9.1 |
CRITICAL
Network
|
openstack
|
os-vif
|
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-15753
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222659
|
7.8 |
HIGH
Local
|
cloudberrylab
|
backup
|
CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the backup plan and add a Pre backup action script that e…
|
CWE-269
Improper Privilege Management
|
CVE-2019-15720
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222660
|
5.5 |
MEDIUM
Local
|
wtfutil
|
wtf
|
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsaf…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-15716
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|