|
222191
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitro_free_pdf_reader
|
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19818
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222192
|
6.5 |
MEDIUM
Network
|
dlink
|
dir-615_t1_firmware
|
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
|
NVD-CWE-noinfo
|
CVE-2019-19743
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222193
|
7.5 |
HIGH
Network
|
roxyfileman
|
roxy_fileman
|
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by u…
|
CWE-22
Path Traversal
|
CVE-2019-19731
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222194
|
6.5 |
MEDIUM
Network
|
cyrus debian fedoraproject canonical
|
imap debian_linux fedora ubuntu_linux
|
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19783
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222195
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. Th…
|
CWE-416
Use After Free
|
CVE-2019-19807
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222196
|
5.5 |
MEDIUM
Local
|
xfig_project fedoraproject debian
|
fig2dev fedora debian_linux
|
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19797
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222197
|
7.8 |
HIGH
Local
|
yabasic
|
yabasic
|
Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19796
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222198
|
7.8 |
HIGH
Local
|
samurai_project
|
samurai
|
samurai 0.7 has a heap-based buffer overflow in canonpath in util.c via a crafted build file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19795
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222199
|
5.9 |
MEDIUM
Network
|
miekg-dns_project
|
miekg-dns
|
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to res…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2019-19794
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222200
|
8.8 |
HIGH
Network
|
cyxtera
|
appgate_sdp
|
In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-19793
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|