|
211841
|
8.8 |
HIGH
Network
|
podofo_project fedoraproject
|
podofo fedora
|
PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose bi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9199
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211842
|
9.8 |
CRITICAL
Network
|
grin
|
grin
|
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
|
CWE-22
Path Traversal
|
CVE-2019-9195
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211843
|
9.8 |
CRITICAL
Network
|
std42
|
elfinder
|
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
|
CWE-78
OS Command
|
CVE-2019-9194
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211844
|
7.5 |
HIGH
Network
|
gnu
|
glibc
|
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CV…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-9192
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211845
|
5.9 |
MEDIUM
Network
|
etsi
|
enterprise_transport_security
|
The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy.
|
CWE-310
Cryptographic Issues
|
CVE-2019-9191
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211846
|
9.8 |
CRITICAL
Network
|
j2store
|
j2store
|
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the product_option[] parameter.
|
CWE-89
SQL Injection
|
CVE-2019-9184
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211847
|
8.8 |
HIGH
Network
|
zzzcms
|
zzzphp
|
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the fi…
|
CWE-352
Origin Validation Error
|
CVE-2019-9182
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211848
|
7.2 |
HIGH
Network
|
schoolcms
|
schoolcms
|
SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the Content-Type to image/php, and placing PHP code aft…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9181
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211849
|
9.8 |
CRITICAL
Network
|
gnu netapp mcafee canonical
|
glibc steelstore_cloud_integrated_storage ontap_select_deploy_administration_utility cloud_backup web_gateway ubuntu_linux
|
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9169
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211850
|
6.1 |
MEDIUM
Network
|
woocommerce
|
woocommerce
|
WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9168
|
2024-11-21 13:51 |
2019-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|