|
223021
|
9.8 |
CRITICAL
Network
|
gogs
|
gogs
|
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
|
CWE-862
Missing Authorization
|
CVE-2019-14544
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223022
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a stack-based buffer overflow in cb_encode_program_id in cobc/typeck.c via crafted COBOL source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14541
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223023
|
9.8 |
CRITICAL
Network
|
sleuthkit fedoraproject
|
the_sleuth_kit fedora
|
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
|
CWE-193
Off-by-one Error
|
CVE-2019-14532
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223024
|
9.8 |
CRITICAL
Network
|
sleuthkit
|
the_sleuth_kit
|
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs/iso9660.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14531
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223025
|
7.5 |
HIGH
Network
|
djangoproject opensuse
|
django leap
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-14235
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223026
|
7.5 |
HIGH
Network
|
djangoproject opensuse
|
django leap
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremel…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-14233
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223027
|
7.5 |
HIGH
Network
|
djangoproject opensuse
|
django leap
|
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-14232
|
2024-11-21 13:26 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223028
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
|
CWE-89
SQL Injection
|
CVE-2019-14529
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223029
|
7.8 |
HIGH
Local
|
gnucobol_project
|
gnucobol
|
GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14528
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223030
|
7.8 |
HIGH
Local
|
schismtracker opensuse
|
schism_tracker leap backports
|
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14524
|
2024-11-21 13:26 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|