|
223081
|
6.1 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16147
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223082
|
6.1 |
MEDIUM
Network
|
padrinorb
|
padrino-contrib
|
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16145
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223083
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-868l_firmware dir-885l_firmware dir-895l_firmware
|
SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 devices allows Authentication Bypass, as demonstrated by a direct request to fold…
|
CWE-287
Improper Authentication
|
CVE-2019-16190
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223084
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. This occurs in application/core/Survey_Common_Action.php,
|
CWE-79
Cross-site Scripting
|
CVE-2019-16173
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223085
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, SuperAdmin. The attack uses a survey group in which the title contains JavaScript…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16172
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223086
|
5.5 |
MEDIUM
Local
|
sysstat_project fedoraproject opensuse canonical debian
|
sysstat fedora leap ubuntu_linux debian_linux
|
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-16167
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223087
|
6.5 |
MEDIUM
Network
|
gnu
|
cflow
|
GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16166
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223088
|
6.5 |
MEDIUM
Network
|
gnu
|
cflow
|
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.
|
CWE-416
Use After Free
|
CVE-2019-16165
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223089
|
6.5 |
MEDIUM
Network
|
myhtml_project
|
myhtml
|
MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16164
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223090
|
7.5 |
HIGH
Network
|
oniguruma_project fedoraproject debian canonical
|
oniguruma fedora debian_linux ubuntu_linux
|
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-16163
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|