|
212611
|
9.8 |
CRITICAL
Network
|
antfin
|
sofa-hessian
|
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.i…
|
CWE-184 CWE-502
Incomplete Blacklist Deserialization of Untrusted Data
|
CVE-2019-9212
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212612
|
7.8 |
HIGH
Local
|
advancemame debian canonical fedoraproject
|
advancecomp debian_linux ubuntu_linux fedora
|
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (T…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2019-9210
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212613
|
9.8 |
CRITICAL
Network
|
phoenixcontact
|
ilc_131_eth_firmware ilc_131_eth\/xc_firmware ilc_151_eth_firmware ilc_151_eth\/xc_firmware ilc_171_eth_2tx_firmware ilc_191_eth_2tx_firmware ilc_191_me\/an_firmware axc_1050_fir…
|
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9201
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212614
|
8.8 |
HIGH
Network
|
freedesktop debian canonical
|
poppler debian_linux ubuntu_linux
|
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It al…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9200
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212615
|
8.8 |
HIGH
Network
|
podofo_project fedoraproject
|
podofo fedora
|
PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose bi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9199
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212616
|
9.8 |
CRITICAL
Network
|
grin
|
grin
|
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
|
CWE-22
Path Traversal
|
CVE-2019-9195
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212617
|
9.8 |
CRITICAL
Network
|
std42
|
elfinder
|
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
|
CWE-78
OS Command
|
CVE-2019-9194
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212618
|
7.5 |
HIGH
Network
|
gnu
|
glibc
|
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CV…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-9192
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212619
|
5.9 |
MEDIUM
Network
|
etsi
|
enterprise_transport_security
|
The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy.
|
CWE-310
Cryptographic Issues
|
CVE-2019-9191
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212620
|
9.8 |
CRITICAL
Network
|
j2store
|
j2store
|
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9184
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|