|
212541
|
7.5 |
HIGH
Network
|
imagemagick opensuse debian canonical
|
imagemagick leap debian_linux ubuntu_linux
|
In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7396
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212542
|
7.5 |
HIGH
Network
|
imagemagick opensuse debian canonical
|
imagemagick leap debian_linux ubuntu_linux
|
In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7395
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212543
|
8.6 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service configuration of all cl…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7390
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212544
|
7.5 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router without authentication vi…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-7389
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212545
|
7.5 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address…
|
CWE-200
Information Exposure
|
CVE-2019-7388
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212546
|
6.5 |
MEDIUM
Network
|
systrome
|
isg-600c_firmware isg-600h_firmware isg-800w_firmware
|
A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. When the export function is called from syst…
|
CWE-22
Path Traversal
|
CVE-2019-7387
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212547
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state.php) does no input validation to the value supplied to the 'New State' (aka ne…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7352
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212548
|
6.5 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted link, which in turn will inject a custom Log message provided by the attacker in t…
|
CWE-74
Injection
|
CVE-2019-7351
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212549
|
7.3 |
HIGH
Network
|
zoneminder
|
zoneminder
|
Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logged-in user, thereby hijacking the victim's account. This occurs because a set o…
|
CWE-384
Session Fixation
|
CVE-2019-7350
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212550
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a vulnerable 'newMonitor[V4LCapturesPerFrame]' parameter value in…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7349
|
2024-11-21 13:48 |
2019-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|