|
223191
|
9.8 |
CRITICAL
Network
|
linux debian canonical opensuse
|
linux_kernel debian_linux ubuntu_linux leap
|
In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17133
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223192
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin through 5.5.4 mishandles custom avatars.
|
CWE-94 CWE-20
Code Injection Improper Input Validation
|
CVE-2019-17132
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223193
|
4.3 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
vBulletin before 5.5.4 allows clickjacking.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-17131
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223194
|
6.5 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2019-17130
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223195
|
5.4 |
MEDIUM
Network
|
vanderbilt
|
redcap
|
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17121
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223196
|
9.8 |
CRITICAL
Network
|
openmpt
|
libopenmpt
|
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API,…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17113
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223197
|
6.1 |
MEDIUM
Network
|
themeisle
|
visualizer
|
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16931
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223198
|
7.5 |
HIGH
Network
|
nlnetlabs canonical
|
unbound ubuntu_linux
|
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
|
CWE-755 CWE-908
Improper Handling of Exceptional Conditions Use of Uninitialized Resource
|
CVE-2019-16866
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223199
|
7.8 |
HIGH
Local
|
linuxmint
|
mintinstall
|
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17080
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223200
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single (a DMA function) from a stack va…
|
NVD-CWE-noinfo
|
CVE-2019-17075
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|