|
223091
|
6.5 |
MEDIUM
Network
|
webassembly
|
binaryen
|
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-se…
|
CWE-617
Reachable Assertion
|
CVE-2019-15758
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223092
|
6.5 |
MEDIUM
Network
|
libmirage_project
|
libmirage
|
libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-15757
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223093
|
7.8 |
HIGH
Local
|
docker apache
|
docker geode
|
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15752
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223094
|
9.1 |
CRITICAL
Network
|
openstack
|
os-vif
|
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-15753
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223095
|
7.8 |
HIGH
Local
|
cloudberrylab
|
backup
|
CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the backup plan and add a Pre backup action script that e…
|
CWE-269
Improper Privilege Management
|
CVE-2019-15720
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223096
|
5.5 |
MEDIUM
Local
|
wtfutil
|
wtf
|
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsaf…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-15716
|
2024-11-21 13:29 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223097
|
5.3 |
MEDIUM
Network
|
entropic_project
|
entropic
|
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations.
|
CWE-22
Path Traversal
|
CVE-2019-15714
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223098
|
6.1 |
MEDIUM
Network
|
my_calendar_project
|
my_calendar
|
The my-calendar plugin before 3.1.10 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15713
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223099
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-15702
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223100
|
8.8 |
HIGH
Network
|
bloodhound_project
|
bloodhound
|
components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawning a child process as the current user on the victim's machine) when the search …
|
CWE-78
OS Command
|
CVE-2019-15701
|
2024-11-21 13:29 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|