|
223081
|
7.5 |
HIGH
Network
|
istio
|
istio
|
Istio before 1.1.13 and 1.2.x before 1.2.4 mishandles regular expressions for long URIs, leading to a denial of service during use of the JWT, VirtualService, HTTPAPISpecBinding, or QuotaSpecBinding …
|
CWE-185
Incorrect Regular Expression
|
CVE-2019-14993
|
2024-11-21 13:27 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223082
|
4.8 |
MEDIUM
Network
|
schben
|
framework
|
Adive Framework through 2.0.7 is affected by XSS in the Create New Table and Create New Navigation Link functions.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14987
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223083
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
In Exiv2 before v0.27.2, there is an integer overflow vulnerability in the WebPImage::getHeaderOffset function in webpimage.cpp. It can lead to a buffer overflow vulnerability and a crash.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14982
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223084
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical opensuse
|
imagemagick debian_linux ubuntu_linux leap
|
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a cr…
|
CWE-369
Divide By Zero
|
CVE-2019-14981
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223085
|
6.5 |
MEDIUM
Network
|
imagemagick opensuse
|
imagemagick leap
|
In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob function that allows an attacker to cause a denial of service by sending a crafte…
|
CWE-416
Use After Free
|
CVE-2019-14980
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223086
|
6.1 |
MEDIUM
Network
|
icmsdev
|
icms
|
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14976
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223087
|
9.8 |
CRITICAL
Network
|
txjia
|
imcat
|
An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
|
CWE-89
SQL Injection
|
CVE-2019-14968
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223088
|
6.1 |
MEDIUM
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14967
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223089
|
7.8 |
HIGH
Local
|
netwrix
|
auditor
|
Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service Netwrix.ADA.StorageAuditService (which writes to t…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14969
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223090
|
8.8 |
HIGH
Network
|
frappe
|
frappe
|
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
|
CWE-89
SQL Injection
|
CVE-2019-14966
|
2024-11-21 13:27 |
2019-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|