|
211181
|
9.8 |
CRITICAL
Network
|
pydio
|
pydio
|
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php fi…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2019-9642
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211182
|
8.8 |
HIGH
Local
|
synaptics
|
sound_device
|
Incorrect access control in the CxUtilSvc component of the Synaptics Sound Device drivers prior to version 2.29 allows a local attacker to increase access privileges to the Windows Registry via an un…
|
NVD-CWE-noinfo
|
CVE-2019-9730
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211183
|
8.8 |
HIGH
Network
|
freenetproject
|
freenet
|
Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
|
CWE-19
Data Processing Errors
|
CVE-2019-9673
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211184
|
6.1 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS 1.9.1 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9647
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211185
|
7.0 |
HIGH
Local
|
tuxera redhat
|
ntfs-3g enterprise_linux_server enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to …
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2019-9755
|
2024-11-21 13:52 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211186
|
6.1 |
MEDIUM
Network
|
vfront
|
vfront
|
VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php azzera parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9839
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211187
|
6.1 |
MEDIUM
Network
|
vfront
|
vfront
|
VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log.php rendering.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9838
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211188
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-9824
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211189
|
4.3 |
MEDIUM
Network
|
otrs
|
otrs
|
An issue was discovered in Open Ticket Request System (OTRS) 7.x before 7.0.5. An attacker who is logged into OTRS as an agent or a customer user can use the search result screens to disclose informa…
|
CWE-200
Information Exposure
|
CVE-2019-9753
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211190
|
8.8 |
HIGH
Network
|
hgiga
|
msr45_isherlock-base msr45_isherlock-useradmin msr45_isherlock-sysinfo msr45_isherlock-user msr35_isherlock-base msr35_isherlock-useradmin msr35_isherlock-sysinfo msr35_isherlock…
|
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_a…
|
CWE-352
Origin Validation Error
|
CVE-2019-9883
|
2024-11-21 13:52 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|