|
212961
|
7.5 |
HIGH
Network
|
live555
|
streaming_media
|
In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-7733
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212962
|
7.5 |
HIGH
Network
|
live555
|
streaming_media
|
In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7732
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212963
|
9.8 |
CRITICAL
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and executes the Backup Database function with a .php filename for the backup's arc…
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-7731
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212964
|
5.7 |
MEDIUM
Network
|
mywebsql
|
mywebsql
|
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
|
CWE-352
Origin Validation Error
|
CVE-2019-7730
|
2024-11-21 13:48 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212965
|
8.1 |
HIGH
Network
|
pmd_project
|
pmd
|
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (either by direct modification or MITM attacks when u…
|
CWE-611
XXE
|
CVE-2019-7722
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212966
|
7.5 |
HIGH
Network
|
nconsulting
|
nc-cms
|
lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-7721
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212967
|
9.8 |
CRITICAL
Network
|
taogogo
|
taocms
|
taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
|
CWE-94
Code Injection
|
CVE-2019-7720
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212968
|
9.8 |
CRITICAL
Network
|
nibbleblog
|
nibbleblog
|
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
|
CWE-94
Code Injection
|
CVE-2019-7719
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212969
|
8.1 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute arbitrary PHP code via admin/index.php?n=databack&c=index&a=dogets…
|
CWE-362
Race Condition
|
CVE-2019-7718
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212970
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-7704
|
2024-11-21 13:48 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|