|
222681
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16351
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222682
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16350
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222683
|
5.5 |
MEDIUM
Local
|
axiosys
|
bento4
|
Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16349
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222684
|
6.5 |
MEDIUM
Network
|
libwav_project
|
libwav
|
marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16348
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222685
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16347
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222686
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16346
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222687
|
9.8 |
CRITICAL
Network
|
egpp
|
sistema_integrado_de_gestion_academica
|
In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attack…
|
CWE-89
SQL Injection
|
CVE-2019-16264
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222688
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16197
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222689
|
7.1 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-16170
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222690
|
9.8 |
CRITICAL
Network
|
fasterxml fedoraproject debian netapp redhat oracle
|
jackson-databind fedora debian_linux steelstore_cloud_integrated_storage oncommand_workflow_automation oncommand_api_services jboss_enterprise_application_platform retail_xstore_…
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16335
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|