|
223271
|
9.8 |
CRITICAL
Network
|
upredsun
|
file_sharing_wizard
|
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar iss…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-16724
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223272
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16754
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223273
|
6.1 |
MEDIUM
Network
|
devise_token_auth_project
|
devise_token_auth
|
An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16751
|
2024-11-21 13:31 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223274
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in Chec…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16748
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223275
|
9.8 |
CRITICAL
Network
|
linux debian canonical fedoraproject opensuse
|
linux_kernel debian_linux ubuntu_linux fedora leap
|
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-16746
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223276
|
7.8 |
HIGH
Local
|
pam-python_project debian canonical
|
pam-python debian_linux ubuntu_linux
|
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
|
NVD-CWE-noinfo
|
CVE-2019-16729
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223277
|
6.1 |
MEDIUM
Network
|
cure53 debian
|
dompurify debian_linux
|
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16728
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223278
|
4.3 |
MEDIUM
Network
|
cacti
|
cacti
|
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-16723
|
2024-11-21 13:31 |
2019-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223279
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
|
NVD-CWE-noinfo
|
CVE-2019-16722
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223280
|
6.5 |
MEDIUM
Network
|
5none
|
nonecms
|
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
|
CWE-352
Origin Validation Error
|
CVE-2019-16721
|
2024-11-21 13:31 |
2019-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|