|
222801
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16352
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222802
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16351
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222803
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16350
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222804
|
5.5 |
MEDIUM
Local
|
axiosys
|
bento4
|
Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16349
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222805
|
6.5 |
MEDIUM
Network
|
libwav_project
|
libwav
|
marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16348
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222806
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16347
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222807
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16346
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222808
|
9.8 |
CRITICAL
Network
|
egpp
|
sistema_integrado_de_gestion_academica
|
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attack…
|
CWE-89
SQL Injection
|
CVE-2019-16264
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222809
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16197
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222810
|
7.1 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-16170
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|