|
222661
|
4.3 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
A clickjacking vulnerability was found in Limesurvey before 3.17.14.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-16175
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222662
|
8.8 |
HIGH
Network
|
limesurvey
|
limesurvey
|
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
|
CWE-611
XXE
|
CVE-2019-16174
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222663
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16147
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222664
|
6.1 |
MEDIUM
Network
|
padrinorb
|
padrino-contrib
|
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16145
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222665
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-868l_firmware dir-885l_firmware dir-895l_firmware
|
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to fold…
|
CWE-287
Improper Authentication
|
CVE-2019-16190
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222666
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
|
CWE-79
Cross-site Scripting
|
CVE-2019-16173
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222667
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16172
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222668
|
5.5 |
MEDIUM
Local
|
sysstat_project fedoraproject opensuse canonical debian
|
sysstat fedora leap ubuntu_linux debian_linux
|
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-16167
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222669
|
6.5 |
MEDIUM
Network
|
gnu
|
cflow
|
GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16166
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222670
|
6.5 |
MEDIUM
Network
|
gnu
|
cflow
|
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.
|
CWE-416
Use After Free
|
CVE-2019-16165
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|