|
218991
|
9.8 |
CRITICAL
Network
|
haxx fedoraproject opensuse netapp oracle debian
|
curl fedora leap cloud_backup snapcenter steelstore_cloud_integrated_storage oncommand_unified_manager oncommand_workflow_automation oncommand_insight http_server enterp…
|
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5482
|
2024-11-21 13:45 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218992
|
9.8 |
CRITICAL
Network
|
haxx fedoraproject netapp oracle debian opensuse
|
curl fedora cloud_backup steelstore solidfire_baseboard_management_controller_firmware enterprise_manager_ops_center communications_operations_monitor oss_support_tools commun…
|
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
|
CWE-415
Double Free
|
CVE-2019-5481
|
2024-11-21 13:45 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218993
|
10.0 |
CRITICAL
Network
|
gitlabhook_project
|
gitlabhook
|
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.
|
CWE-78
OS Command
|
CVE-2019-5485
|
2024-11-21 13:45 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218994
|
7.5 |
HIGH
Network
|
bower
|
bower
|
Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows attackers to write arbitrary files when a malicious package is ext…
|
CWE-22
Path Traversal
|
CVE-2019-5484
|
2024-11-21 13:45 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218995
|
6.1 |
MEDIUM
Network
|
ss-proj
|
shirasagi
|
Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
CWE-601
Open Redirect
|
CVE-2019-6009
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218996
|
8.8 |
HIGH
Network
|
linecorp
|
apng-drawable
|
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-6007
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218997
|
9.8 |
CRITICAL
Network
|
kddi
|
smart_tv_box_firmware
|
Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary operations on the device without user's intent, such as installing arbitrary soft…
|
NVD-CWE-noinfo
|
CVE-2019-6005
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218998
|
6.1 |
MEDIUM
Network
|
fujixerox
|
apeosware_management_suite apeosware_management_suite_2
|
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web …
|
CWE-601
Open Redirect
|
CVE-2019-6004
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218999
|
6.1 |
MEDIUM
Network
|
ec-cube
|
amazon_pay
|
Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6003
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219000
|
8.8 |
HIGH
Network
|
panasonic
|
video_insight_vms
|
SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2019-5996
|
2024-11-21 13:45 |
2019-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|