|
212741
|
9.8 |
CRITICAL
Network
|
uvnc siemens
|
ultravnc sinumerik_pcu_base_win7_software\/ipc sinumerik_pcu_base_win10_software\/ipc sinumerik_access_mymachine\/p2p
|
UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network co…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-8262
|
2024-11-21 13:49 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212742
|
9.8 |
CRITICAL
Network
|
uvnc
|
ultravnc
|
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multiplication overflow. This attack appears to be exploitable via network connectivit…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8261
|
2024-11-21 13:49 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212743
|
9.8 |
CRITICAL
Network
|
uvnc
|
ultravnc
|
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This v…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8260
|
2024-11-21 13:49 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212744
|
7.5 |
HIGH
Network
|
uvnc siemens
|
ultravnc sinumerik_pcu_base_win7_software\/ipc sinumerik_pcu_base_win10_software\/ipc sinumerik_access_mymachine\/p2p
|
UltraVNC revision 1198 contains multiple memory leaks (CWE-655) in VNC client code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vu…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-8259
|
2024-11-21 13:49 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212745
|
9.8 |
CRITICAL
Network
|
uvnc siemens
|
ultravnc sinumerik_pcu_base_win7_software\/ipc sinumerik_pcu_base_win10_software\/ipc sinumerik_access_mymachine\/p2p
|
UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-8258
|
2024-11-21 13:49 |
2019-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212746
|
5.4 |
MEDIUM
Network
|
vanillaforums
|
vanilla_forums
|
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8279
|
2024-11-21 13:49 |
2019-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212747
|
6.1 |
MEDIUM
Network
|
invisioncommunity
|
invision_power_board
|
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8278
|
2024-11-21 13:49 |
2019-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212748
|
6.1 |
MEDIUM
Network
|
maccms
|
maccms
|
Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2019-8410
|
2024-11-21 13:49 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212749
|
9.8 |
CRITICAL
Network
|
webkitgtk opensuse canonical
|
webkitgtk webkitgtk\+ leap ubuntu_linux
|
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, whi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-8375
|
2024-11-21 13:49 |
2019-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212750
|
6.1 |
MEDIUM
Network
|
getbootstrap f5 redhat tenable
|
bootstrap big-ip_local_traffic_manager big-ip_application_security_manager big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_accelera…
|
In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8331
|
2024-11-21 13:49 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|