|
211771
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular express…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9023
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211772
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow a…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9021
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211773
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap …
|
CWE-125 CWE-416
Out-of-bounds Read Use After Free
|
CVE-2019-9020
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211774
|
6.8 |
MEDIUM
Physics
|
british_airways
|
entertainment_system
|
The British Airways Entertainment System, as installed on Boeing 777-36N(ER) and possibly other aircraft, does not prevent the USB charging/data-transfer feature from interacting with USB keyboard an…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9019
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211775
|
6.1 |
MEDIUM
Network
|
mopcms
|
mopcms
|
An XSS vulnerability was discovered in MOPCMS through 2018-11-30. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[name] parameter in a mod=col…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9016
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211776
|
9.1 |
CRITICAL
Network
|
mopcms
|
mopcms
|
A Path Traversal vulnerability was discovered in MOPCMS through 2018-11-30, leading to deletion of unexpected critical files. The exploitation point is in the "column management" function. The path a…
|
CWE-22
Path Traversal
|
CVE-2019-9015
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211777
|
7.5 |
HIGH
Network
|
eclipse
|
wakaama
|
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-9004
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211778
|
7.5 |
HIGH
Network
|
linux netapp canonical opensuse
|
linux_kernel solidfire hci_management_node snapprotect cn1610_firmware ubuntu_linux leap
|
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by …
|
CWE-416
Use After Free
|
CVE-2019-9003
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211779
|
9.8 |
CRITICAL
Network
|
tiny_issue_project pixeline
|
tiny_issue bugs
|
An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the ins…
|
CWE-862
Missing Authorization
|
CVE-2019-9002
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211780
|
7.5 |
HIGH
Network
|
torproject
|
tor
|
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-8955
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|