|
212301
|
9.8 |
CRITICAL
Network
|
php netapp
|
php storage_automation_store
|
An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with …
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-9025
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212302
|
7.5 |
HIGH
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9024
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212303
|
7.5 |
HIGH
Network
|
php debian canonical netapp
|
php debian_linux ubuntu_linux storage_automation_store
|
An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse mem…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9022
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212304
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular express…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9023
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212305
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow a…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9021
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212306
|
9.8 |
CRITICAL
Network
|
php debian canonical netapp opensuse
|
php debian_linux ubuntu_linux storage_automation_store leap
|
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap …
|
CWE-125 CWE-416
Out-of-bounds Read Use After Free
|
CVE-2019-9020
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212307
|
6.8 |
MEDIUM
Physics
|
british_airways
|
entertainment_system
|
The British Airways Entertainment System, as installed on Boeing 777-36N(ER) and possibly other aircraft, does not prevent the USB charging/data-transfer feature from interacting with USB keyboard an…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-9019
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212308
|
6.1 |
MEDIUM
Network
|
mopcms
|
mopcms
|
An XSS vulnerability was discovered in MOPCMS through 2018-11-30. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[name] parameter in a mod=col…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9016
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212309
|
9.1 |
CRITICAL
Network
|
mopcms
|
mopcms
|
A Path Traversal vulnerability was discovered in MOPCMS through 2018-11-30, leading to deletion of unexpected critical files. The exploitation point is in the "column management" function. The path a…
|
CWE-22
Path Traversal
|
CVE-2019-9015
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212310
|
7.5 |
HIGH
Network
|
eclipse
|
wakaama
|
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-9004
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|