|
223091
|
7.5 |
HIGH
Network
|
k-takata
|
onigmo
|
Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-16162
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223092
|
6.5 |
MEDIUM
Network
|
sqlite netapp canonical fedoraproject debian tenable oracle mcafee
|
sqlite steelstore_cloud_integrated_storage oncommand_workflow_automation oncommand_insight ontap_select_deploy_administration_utility active_iq_unified_manager santricity_unified_ma…
|
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the …
|
CWE-369
Divide By Zero
|
CVE-2019-16168
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223093
|
7.5 |
HIGH
Network
|
k-takata
|
onigmo
|
Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16161
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223094
|
7.5 |
HIGH
Network
|
nic opensuse fedoraproject debian
|
bird backports_sle fedora debian_linux
|
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16159
|
2024-11-21 13:30 |
2019-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223095
|
6.1 |
MEDIUM
Network
|
sakailms
|
sakai
|
Sakai through 12.6 allows XSS via a chat user name.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16148
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223096
|
4.8 |
MEDIUM
Network
|
getgophish
|
gophish
|
Gophish through 0.8.0 allows XSS via a username.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16146
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223097
|
9.8 |
CRITICAL
Network
|
atutor
|
atutor
|
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the …
|
CWE-863
Incorrect Authorization
|
CVE-2019-16114
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223098
|
7.5 |
HIGH
Network
|
generator-rs_project
|
generator-rs
|
An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-16144
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223099
|
9.8 |
CRITICAL
Network
|
blake2
|
blake2-rust
|
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-16143
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223100
|
9.8 |
CRITICAL
Network
|
renderdocs-rs_project
|
renderdocs-rs
|
An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application.
|
CWE-20
Improper Input Validation
|
CVE-2019-16142
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|