|
222011
|
9.8 |
CRITICAL
Network
|
ffmpeg canonical debian
|
ffmpeg ubuntu_linux debian_linux
|
FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17542
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222012
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager is mishandled in coders/jpeg.c.
|
CWE-416
Use After Free
|
CVE-2019-17541
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222013
|
8.8 |
HIGH
Network
|
imagemagick debian
|
imagemagick debian_linux
|
ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17540
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222014
|
9.8 |
CRITICAL
Network
|
ffmpeg debian canonical
|
ffmpeg debian_linux ubuntu_linux
|
In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17539
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222015
|
8.8 |
HIGH
Network
|
centreon
|
centreon
|
Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-20…
|
CWE-78
OS Command
|
CVE-2019-17501
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222016
|
7.5 |
HIGH
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
|
CWE-22
Path Traversal
|
CVE-2019-17538
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222017
|
7.5 |
HIGH
Network
|
jnoj
|
jiangnan_online_judge
|
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
|
CWE-22
Path Traversal
|
CVE-2019-17537
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222018
|
4.9 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17536
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222019
|
6.1 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17535
|
2024-11-21 13:32 |
2019-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222020
|
8.8 |
HIGH
Network
|
libvips
|
libvips
|
vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.
|
CWE-416
Use After Free
|
CVE-2019-17534
|
2024-11-21 13:32 |
2019-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|