|
222761
|
6.1 |
MEDIUM
Network
|
sunhater
|
kcfinder
|
A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditor…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14315
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222762
|
5.4 |
MEDIUM
Network
|
veeam
|
one_reporter
|
Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in CommonDataHandlerReadOnly.ashx.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14298
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222763
|
5.4 |
MEDIUM
Network
|
veeam
|
one_reporter
|
Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in CommonDataHandlerReadOnly.ashx.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14297
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222764
|
7.8 |
HIGH
Local
|
upx_project
|
upx
|
canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impact via a crafted UPX…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-14296
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222765
|
5.5 |
MEDIUM
Local
|
upx_project
|
upx
|
An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14295
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222766
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
An issue was discovered in Xpdf 4.01.01. There is a use-after-free in the function JPXStream::fillReadBuf at JPXStream.cc, due to an out of bounds read.
|
CWE-125 CWE-416
Out-of-bounds Read Use After Free
|
CVE-2019-14294
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222767
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 2.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14293
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222768
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA!=6 case 1.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14292
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222769
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 3.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14291
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222770
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-14290
|
2024-11-21 13:26 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|