|
212131
|
7.5 |
HIGH
Network
|
matio_project
|
matio
|
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow problem in the function ReadNextCell() in mat5.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9027
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212132
|
7.5 |
HIGH
Network
|
matio_project
|
matio
|
An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a heap-based buffer overflow in the function InflateVarName() in inflate.c when called from ReadNextCell in …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9026
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212133
|
9.8 |
CRITICAL
Network
|
php netapp
|
php storage_automation_store
|
An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-9025
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212134
|
7.5 |
HIGH
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9024
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212135
|
7.5 |
HIGH
Network
|
php debian canonical netapp
|
php debian_linux ubuntu_linux storage_automation_store
|
An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse mem…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9022
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212136
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular express…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9023
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212137
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow a…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9021
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212138
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap …
|
CWE-125 CWE-416
Out-of-bounds Read Use After Free
|
CVE-2019-9020
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212139
|
6.8 |
MEDIUM
Physics
|
british_airways
|
entertainment_system
|
The British Airways Entertainment System, as installed on Boeing 777-36N(ER) and possibly other aircraft, does not prevent the USB charging/data-transfer feature from interacting with USB keyboard an…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9019
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212140
|
6.1 |
MEDIUM
Network
|
mopcms
|
mopcms
|
An XSS vulnerability was discovered in MOPCMS through 2018-11-30. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[name] parameter in a mod=col…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9016
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|