|
211231
|
9.8 |
CRITICAL
Network
|
mozilla redhat
|
firefox firefox_esr thunderbird enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory c…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9792
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211232
|
9.8 |
CRITICAL
Network
|
mozilla
|
thunderbird firefox firefox_esr
|
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially e…
|
CWE-416
Use After Free
|
CVE-2019-9790
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211233
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9789
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211234
|
9.8 |
CRITICAL
Network
|
mozilla redhat
|
firefox firefox_esr thunderbird enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the con…
|
CWE-843
Type Confusion
|
CVE-2019-9791
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211235
|
9.8 |
CRITICAL
Network
|
mozilla redhat
|
firefox firefox_esr thunderbird enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we pres…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9788
|
2024-11-21 13:52 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211236
|
6.1 |
MEDIUM
Network
|
wordfence
|
wordfence
|
The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is not a valid vulnerability in the context of the Wordfence WordPress plugin as t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9669
|
2024-11-21 13:52 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211237
|
10.0 |
CRITICAL
Network
|
envoyproxy
|
envoy
|
Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/../admin, to bypass access control, e.g., a block on /admin. A backend server co…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-9901
|
2024-11-21 13:52 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211238
|
8.3 |
HIGH
Network
|
envoyproxy redhat
|
envoy openshift_service_mesh
|
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL char…
|
CWE-74
Injection
|
CVE-2019-9900
|
2024-11-21 13:52 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211239
|
6.5 |
MEDIUM
Network
|
google
|
tensorflow
|
NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9635
|
2024-11-21 13:52 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211240
|
9.8 |
CRITICAL
Network
|
western_digital
|
my_cloud_mirror_gen_2_firmware my_cloud_ex2_ultra_firmware my_cloud_ex2100_firmware my_cloud_ex4100 my_cloud_dl2100 my_cloud_dl4100_firmware my_cloud_pr2100_firmware my_cloud_pr4…
|
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9951
|
2024-11-21 13:52 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|