|
222121
|
8.8 |
HIGH
Network
|
sitemagic
|
sitemagic
|
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via s…
|
CWE-352
Origin Validation Error
|
CVE-2019-18220
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222122
|
7.5 |
HIGH
Network
|
haproxy
|
haproxy
|
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if co…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-18277
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222123
|
6.1 |
MEDIUM
Network
|
sitemagic
|
sitemagic
|
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection with…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18219
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222124
|
7.8 |
HIGH
Local
|
nipper-ng_project
|
nipper-ng
|
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17424
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222125
|
7.5 |
HIGH
Network
|
universal_office_converter_project
|
universal_office_converter
|
The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17400
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222126
|
8.1 |
HIGH
Network
|
libssh2 fedoraproject opensuse debian netapp
|
libssh2 fedora leap debian_linux element_software ontap_select_deploy_administration_utility solidfire hci_management_node active_iq_unified_manager bootstrap_os
|
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a s…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-17498
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222127
|
9.8 |
CRITICAL
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware
|
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 bef…
|
NVD-CWE-noinfo
|
CVE-2019-18225
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222128
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_501_firmware
|
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18203
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222129
|
9.8 |
CRITICAL
Network
|
gnu
|
libidn2
|
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18224
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222130
|
7.8 |
HIGH
Local
|
file_project debian opensuse netapp fedoraproject canonical
|
file debian_linux leap active_iq_unified_manager fedora ubuntu_linux
|
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18218
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|