|
223561
|
9.8 |
CRITICAL
Network
|
moddable
|
xs moddable
|
In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript code to xst.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16366
|
2024-11-21 13:30 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223562
|
5.5 |
MEDIUM
Local
|
beego
|
beego
|
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16355
|
2024-11-21 13:30 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223563
|
4.7 |
MEDIUM
Local
|
beego
|
beego
|
The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file creation within a directory with weak permissions.
|
CWE-362 CWE-732
Race Condition Incorrect Permission Assignment for Critical Resource
|
CVE-2019-16354
|
2024-11-21 13:30 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223564
|
7.5 |
HIGH
Network
|
geautomation
|
proficy
|
Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic from a remote device, as demonstrated by an RX7i device.
|
NVD-CWE-noinfo
|
CVE-2019-16353
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223565
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16352
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223566
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16351
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223567
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16350
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223568
|
5.5 |
MEDIUM
Local
|
axiosys
|
bento4
|
Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16349
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223569
|
6.5 |
MEDIUM
Network
|
libwav_project
|
libwav
|
marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16348
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223570
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16347
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|