|
223061
|
8.8 |
HIGH
Network
|
leaftecnologia
|
leaf_admin
|
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14755
|
2024-11-21 13:27 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223062
|
8.0 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could…
|
CWE-352
Origin Validation Error
|
CVE-2019-15062
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223063
|
9.1 |
CRITICAL
Network
|
stb_project
|
stb
|
stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15058
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223064
|
9.8 |
CRITICAL
Network
|
gradle
|
gradle
|
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subs…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-15052
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223065
|
6.8 |
MEDIUM
Network
|
atlassian
|
html_include_and_replace_macro
|
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15053
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223066
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15050
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223067
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15049
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223068
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15048
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223069
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15047
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223070
|
6.1 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14974
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|