|
222181
|
8.8 |
HIGH
Network
|
contao
|
contao
|
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-19745
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222182
|
5.3 |
MEDIUM
Network
|
contao
|
contao
|
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2019-19714
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222183
|
7.8 |
HIGH
Local
|
ivanti
|
workspace_control
|
In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Prefere…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19675
|
2024-11-21 13:35 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222184
|
5.3 |
MEDIUM
Network
|
contao
|
contao
|
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19712
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222185
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2f…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19815
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222186
|
7.8 |
HIGH
Local
|
linux canonical debian netapp
|
linux_kernel ubuntu_linux debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager data_availability_services solidfire hci_management_node aff_a700s_firmwar…
|
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a va…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19816
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222187
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19814
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222188
|
5.5 |
MEDIUM
Local
|
linux canonical debian netapp
|
linux_kernel ubuntu_linux debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager data_availability_services solidfire hci_management_node aff_a700s_firmwar…
|
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/…
|
CWE-416
Use After Free
|
CVE-2019-19813
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222189
|
6.5 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
|
NVD-CWE-noinfo
|
CVE-2019-19830
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222190
|
9.8 |
CRITICAL
Network
|
drupal
|
views_dynamic_field
|
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involv…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-19826
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|