|
211551
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arb…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9139
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211552
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed PhotoShop file that is mishandled by Daview.exe. Attackers could exploit this a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9138
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211553
|
7.8 |
HIGH
Local
|
hmtalk
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could exploit this and a…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-9137
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211554
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that is mishandled by Daview.exe. Attackers could explo…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9136
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211555
|
7.8 |
HIGH
Local
|
datools
|
daviewindy
|
DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed DIB format file that is mishandled by Daview.exe. Attackers could exploit th…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9135
|
2024-11-21 13:51 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211556
|
9.8 |
CRITICAL
Network
|
xinruidz
|
sundray_wan_controller_firmware
|
WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters i…
|
CWE-78
OS Command
|
CVE-2019-9161
|
2024-11-21 13:51 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211557
|
9.8 |
CRITICAL
Network
|
xinruidz
|
sundray_wan_controller_firmware
|
WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker to login to the system via SSH (on TCP port 22345) and escalate to root (becau…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-9160
|
2024-11-21 13:51 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211558
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 5 of 5).
|
CWE-200
Information Exposure
|
CVE-2019-9225
|
2024-11-21 13:51 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211559
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 4 of 5).
|
CWE-862
Missing Authorization
|
CVE-2019-9224
|
2024-11-21 13:51 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211560
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2019-9223
|
2024-11-21 13:51 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|