|
223101
|
8.8 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
|
NVD-CWE-noinfo
|
CVE-2019-14392
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223102
|
5.5 |
MEDIUM
Local
|
gnu opensuse canonical netapp
|
binutils leap ubuntu_linux solidfire hci_management_node
|
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14444
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223103
|
6.5 |
MEDIUM
Network
|
libav debian
|
libav debian_linux
|
An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by av…
|
CWE-369
Divide By Zero
|
CVE-2019-14443
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223104
|
6.5 |
MEDIUM
Network
|
libav debian
|
libav debian_linux
|
In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cau…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-14442
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223105
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_…
|
NVD-CWE-noinfo
|
CVE-2019-14441
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223106
|
3.3 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
|
NVD-CWE-noinfo
|
CVE-2019-14391
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223107
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
|
CWE-79
Cross-site Scripting
|
CVE-2019-14390
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223108
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
|
NVD-CWE-noinfo
|
CVE-2019-14389
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223109
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
|
NVD-CWE-noinfo
|
CVE-2019-14388
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223110
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
|
CWE-79
Cross-site Scripting
|
CVE-2019-14387
|
2024-11-21 13:26 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|