|
223171
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-14248
|
2024-11-21 13:26 |
2019-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223172
|
5.5 |
MEDIUM
Local
|
mpg321_project
|
mpg321
|
The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14247
|
2024-11-21 13:26 |
2019-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223173
|
7.5 |
HIGH
Network
|
haproxy
|
proxyprotocol
|
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webse…
|
CWE-20
Improper Input Validation
|
CVE-2019-14243
|
2024-11-21 13:26 |
2019-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223174
|
7.5 |
HIGH
Network
|
haproxy
|
haproxy
|
HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-14241
|
2024-11-21 13:26 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223175
|
8.1 |
HIGH
Network
|
wcms
|
wcms
|
WCMS v0.3.2 has a CSRF vulnerability, with resultant directory traversal, to modify index.html via the /wex/html.php?finish=../index.html URI.
|
CWE-352 CWE-22
Origin Validation Error Path Traversal
|
CVE-2019-14240
|
2024-11-21 13:26 |
2019-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223176
|
9.8 |
CRITICAL
Network
|
onionbuzz
|
onionbuzz
|
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.2 for WordPress. One could exploit the points parameter in the ob_get_results ajax nopriv handler due to there being no s…
|
CWE-89
SQL Injection
|
CVE-2019-14231
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223177
|
9.8 |
CRITICAL
Network
|
onionbuzz
|
onionbuzz
|
An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitizati…
|
CWE-89
SQL Injection
|
CVE-2019-14230
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223178
|
7.5 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14215
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223179
|
7.5 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Service when deleting pages in a document that contains only one page by calling …
|
NVD-CWE-noinfo
|
CVE-2019-14214
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223180
|
7.5 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of the signature dictionary during CSG_SignatureF and CPDF_Document destruction.
|
NVD-CWE-noinfo
|
CVE-2019-14213
|
2024-11-21 13:26 |
2019-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|