|
223181
|
9.8 |
CRITICAL
Network
|
xerox
|
atlalink_firmware
|
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
|
NVD-CWE-noinfo
|
CVE-2019-17184
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223182
|
7.2 |
HIGH
Network
|
fecmall
|
fecmall
|
An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-end restriction and upload PHP code to the webserv…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17188
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223183
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of ti…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-16865
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223184
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader
|
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-17183
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223185
|
7.8 |
HIGH
Local
|
valvesoftware
|
steam_client
|
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This …
|
CWE-22
Path Traversal
|
CVE-2019-17180
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223186
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1
|
CWE-79
Cross-site Scripting
|
CVE-2019-17179
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223187
|
7.5 |
HIGH
Network
|
freerdp lodev opensuse
|
freerdp lodepng leap
|
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argum…
|
CWE-252 CWE-401
Unchecked Return Value Missing Release of Memory after Effective Lifetime
|
CVE-2019-17178
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223188
|
7.5 |
HIGH
Network
|
freerdp opensuse
|
freerdp leap
|
libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc retur…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-17177
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223189
|
7.5 |
HIGH
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
|
CWE-22
Path Traversal
|
CVE-2019-17175
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223190
|
9.8 |
CRITICAL
Network
|
liferay
|
liferay_portal
|
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16891
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|