|
222601
|
7.8 |
HIGH
Local
|
radare fedoraproject
|
radare2 fedora
|
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the …
|
CWE-77
Command Injection
|
CVE-2019-14745
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222602
|
6.6 |
MEDIUM
Physics
|
valvesoftware
|
steam_client
|
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM acces…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-14743
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222603
|
8.8 |
HIGH
Network
|
osticket
|
osticket
|
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically f…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-14749
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222604
|
5.4 |
MEDIUM
Network
|
osticket
|
osticket
|
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality h…
|
CWE-79 CWE-434
Cross-site Scripting Unrestricted Upload of File with Dangerous Type
|
CVE-2019-14748
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222605
|
7.8 |
HIGH
Local
|
kde debian fedoraproject opensuse canonical redhat
|
kconfig debian_linux fedora backports_sle ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling…
|
CWE-78
OS Command
|
CVE-2019-14744
|
2024-11-21 13:27 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222606
|
8.8 |
HIGH
Network
|
adplug_project fedoraproject
|
adplug fedora
|
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14734
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222607
|
8.8 |
HIGH
Network
|
adplug_project fedoraproject
|
adplug fedora
|
AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14733
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222608
|
8.8 |
HIGH
Network
|
adplug_project fedoraproject
|
adplug fedora
|
AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14732
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222609
|
5.4 |
MEDIUM
Network
|
cnezsoft
|
zentao
|
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14731
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222610
|
9.8 |
CRITICAL
Network
|
microdigital
|
mdc-n4090_firmware mdc-n4090w_firmware mdc-n2190v_firmware
|
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, th…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-14709
|
2024-11-21 13:27 |
2019-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|