|
219741
|
9.1 |
CRITICAL
Network
|
linaro
|
op-tee
|
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-25052
|
2024-11-21 13:39 |
2021-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219742
|
7.8 |
HIGH
Local
|
gnu debian fedoraproject
|
aspell debian_linux fedora
|
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25051
|
2024-11-21 13:39 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219743
|
7.8 |
HIGH
Local
|
osgeo
|
gdal
|
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-25050
|
2024-11-21 13:39 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219744
|
7.1 |
HIGH
Local
|
openbsd
|
libressl
|
LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx).
|
CWE-125
Out-of-bounds Read
|
CVE-2019-25049
|
2024-11-21 13:39 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219745
|
7.1 |
HIGH
Local
|
openbsd
|
libressl
|
LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print).
|
CWE-125
Out-of-bounds Read
|
CVE-2019-25048
|
2024-11-21 13:39 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219746
|
6.1 |
MEDIUM
Network
|
greenbone
|
greenbone_security_assistant greenbone_os
|
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
|
CWE-79
Cross-site Scripting
|
CVE-2019-25047
|
2024-11-21 13:39 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219747
|
6.1 |
MEDIUM
Network
|
cerberusftp
|
ftp_server
|
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
|
CWE-79
Cross-site Scripting
|
CVE-2019-25046
|
2024-11-21 13:39 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219748
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel solidfire_baseboard_management_controller_firmware cloud_backup solidfire_\&_hci_management_node h500s_firmware h700s_firmware h300e_firmware h500e_firmware h…
|
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
|
CWE-416
Use After Free
|
CVE-2019-25045
|
2024-11-21 13:39 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219749
|
5.5 |
MEDIUM
Local
|
versa-networks
|
versa_director versa_analytics versa_operating_system
|
In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or key derivation function prior to storage. Popular hashing algorithms based on the…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-25030
|
2024-11-21 13:39 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219750
|
9.8 |
CRITICAL
Network
|
versa-networks
|
versa_director
|
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are pos…
|
CWE-77
Command Injection
|
CVE-2019-25029
|
2024-11-21 13:39 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|