|
222811
|
6.1 |
MEDIUM
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17489
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222812
|
6.1 |
MEDIUM
Network
|
b3log
|
symphony
|
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17488
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222813
|
8.8 |
HIGH
Network
|
eleopard
|
animate_it\!
|
The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
|
CWE-352
Origin Validation Error
|
CVE-2019-17386
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222814
|
9.8 |
CRITICAL
Network
|
nongnu debian canonical fedoraproject opensuse
|
libntlm debian_linux ubuntu_linux fedora leap backports_sle
|
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17455
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222815
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17454
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222816
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17453
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222817
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dum…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17452
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222818
|
6.5 |
MEDIUM
Network
|
gnu opensuse canonical
|
binutils leap ubuntu_linux
|
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-17451
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222819
|
6.5 |
MEDIUM
Network
|
gnu opensuse canonical
|
binutils leap ubuntu_linux
|
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recurs…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-17450
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222820
|
6.7 |
MEDIUM
Local
|
avira
|
software_updater
|
Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privi…
|
CWE-426
Untrusted Search Path
|
CVE-2019-17449
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|