|
223211
|
6.5 |
MEDIUM
Network
|
totaljs
|
total.js_cms
|
An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cooki…
|
CWE-327 CWE-330
Use of a Broken or Risky Cryptographic Algorithm Use of Insufficiently Random Values
|
CVE-2019-15955
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223212
|
8.8 |
HIGH
Network
|
totaljs
|
total.js_cms
|
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly ma…
|
CWE-862
Missing Authorization
|
CVE-2019-15953
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223213
|
9.9 |
CRITICAL
Network
|
totaljs
|
total.js_cms
|
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget wi…
|
CWE-862
Missing Authorization
|
CVE-2019-15954
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223214
|
8.8 |
HIGH
Network
|
totaljs
|
total.js_cms
|
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted director…
|
CWE-22
Path Traversal
|
CVE-2019-15952
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223215
|
7.5 |
HIGH
Network
|
bitcoin
|
bitcoin_core
|
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-15947
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223216
|
6.4 |
MEDIUM
Physics
|
opensc_project debian fedoraproject
|
opensc debian_linux fedora
|
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15946
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223217
|
6.4 |
MEDIUM
Physics
|
opensc_project debian fedoraproject
|
opensc debian_linux fedora
|
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-15945
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223218
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer.
|
CWE-252
Unchecked Return Value
|
CVE-2019-15942
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223219
|
5.9 |
MEDIUM
Network
|
opencv opensuse debian
|
opencv leap debian_linux
|
An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modules/objdetect/src/hog.cpp.
|
CWE-369
Divide By Zero
|
CVE-2019-15939
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223220
|
9.8 |
CRITICAL
Network
|
pengutronix
|
barebox
|
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15938
|
2024-11-21 13:29 |
2019-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|