|
223101
|
7.5 |
HIGH
Network
|
once_cell_project
|
once_cell
|
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
|
CWE-20
Improper Input Validation
|
CVE-2019-16141
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223102
|
9.8 |
CRITICAL
Network
|
isahc_project
|
isahc
|
An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion.
|
CWE-416
Use After Free
|
CVE-2019-16140
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223103
|
9.8 |
CRITICAL
Network
|
compact_arena_project
|
compact_arena
|
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-16139
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223104
|
9.8 |
CRITICAL
Network
|
image-rs
|
image
|
An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len is called on an uninitialized vector, leading to a use-after-free and arbitrary…
|
CWE-416
Use After Free
|
CVE-2019-16138
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223105
|
7.5 |
HIGH
Network
|
spin-rs_project
|
spin-rs
|
An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclus…
|
CWE-662
Improper Synchronization
|
CVE-2019-16137
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223106
|
6.5 |
MEDIUM
Network
|
weaver
|
eteams_oa
|
An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Spec…
|
CWE-613
Insufficient Session Expiration
|
CVE-2019-16133
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223107
|
6.5 |
MEDIUM
Network
|
phpok
|
oklite
|
An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.
|
CWE-22
Path Traversal
|
CVE-2019-16132
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223108
|
8.8 |
HIGH
Network
|
phpok
|
oklite
|
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-16131
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223109
|
6.1 |
MEDIUM
Network
|
hgw168cc
|
yii-cms
|
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16130
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223110
|
6.1 |
MEDIUM
Network
|
getgrav
|
grav_cms
|
Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16126
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|