|
222241
|
8.8 |
HIGH
Network
|
centreon
|
centreon_web
|
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this…
|
CWE-78
OS Command
|
CVE-2019-17107
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222242
|
6.5 |
MEDIUM
Network
|
centreon
|
centreon_web
|
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-17106
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222243
|
7.5 |
HIGH
Network
|
centreon
|
centreon_vm
|
In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is not set.
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2019-17104
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222244
|
7.5 |
HIGH
Network
|
auth0
|
auth0.net
|
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
|
CWE-287
Improper Authentication
|
CVE-2019-16929
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222245
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17262
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222246
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17261
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222247
|
7.8 |
HIGH
Local
|
mpc-hc
|
mpc-hc
|
MPC-HC through 1.7.13 allows a Read Access Violation on a Block Data Move starting at mpc_hc!memcpy+0x000000000000004e.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17260
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222248
|
7.8 |
HIGH
Local
|
kmplayer
|
kmplayer
|
KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17259
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222249
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000000839c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17258
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222250
|
5.5 |
MEDIUM
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR+0x000000000002af80.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2019-17257
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|