|
213561
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codecs/Ap4BitStream.cpp, a similar issue to CVE-2017-14645. It can be triggered by s…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8378
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213562
|
7.8 |
HIGH
Local
|
broadcom fedoraproject
|
tcpreplay fedora
|
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcprep…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-8377
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213563
|
7.8 |
HIGH
Local
|
broadcom fedoraproject
|
tcpreplay fedora
|
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-8376
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213564
|
6.1 |
MEDIUM
Network
|
verydows
|
verydows
|
Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8363
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213565
|
7.5 |
HIGH
Network
|
dedecms
|
dedecms
|
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that conta…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-8362
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213566
|
6.1 |
MEDIUM
Network
|
responsive_video_news_script_project
|
responsive_video_news_script
|
PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML injection or URL redirection.
|
CWE-79
Cross-site Scripting
|
CVE-2019-8361
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213567
|
9.8 |
CRITICAL
Network
|
themerig
|
find_a_place_cms_directory
|
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
|
CWE-89
SQL Injection
|
CVE-2019-8360
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213568
|
8.1 |
HIGH
Network
|
hiawatha-webserver
|
hiawatha
|
In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.
|
CWE-22
Path Traversal
|
CVE-2019-8358
|
2024-11-21 13:49 |
2019-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213569
|
5.5 |
MEDIUM
Local
|
sound_exchange_project
|
sound_exchange
|
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-8357
|
2024-11-21 13:49 |
2019-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213570
|
5.5 |
MEDIUM
Local
|
sound_exchange_project
|
sound_exchange
|
An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buff…
|
CWE-787 CWE-129
Out-of-bounds Write Improper Validation of Array Index
|
CVE-2019-8356
|
2024-11-21 13:49 |
2019-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|