|
211831
|
6.1 |
MEDIUM
Network
|
baigo
|
baigo_cms
|
An issue was discovered in baigo CMS 2.1.1. There is a persistent XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the opt[base][BG_SITE_NAME] parameter to th…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9226
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211832
|
9.8 |
CRITICAL
Network
|
live555 opensuse debian
|
streaming_media leap backports_sle debian_linux
|
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
|
NVD-CWE-noinfo
|
CVE-2019-9215
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211833
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9214
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211834
|
5.5 |
MEDIUM
Local
|
wireshark debian canonical opensuse
|
wireshark debian_linux ubuntu_linux leap
|
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with e…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-9209
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211835
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-9208
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211836
|
6.5 |
MEDIUM
Network
|
gnu fedoraproject suse
|
pspp fedora backports
|
There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
|
CWE-617
Reachable Assertion
|
CVE-2019-9211
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211837
|
9.8 |
CRITICAL
Network
|
antfin
|
sofa-hessian
|
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.i…
|
CWE-184 CWE-502
Incomplete Blacklist Deserialization of Untrusted Data
|
CVE-2019-9212
|
2024-11-21 13:51 |
2019-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211838
|
7.8 |
HIGH
Local
|
advancemame debian canonical fedoraproject
|
advancecomp debian_linux ubuntu_linux fedora
|
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (T…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2019-9210
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211839
|
9.8 |
CRITICAL
Network
|
phoenixcontact
|
ilc_131_eth_firmware ilc_131_eth\/xc_firmware ilc_151_eth_firmware ilc_151_eth\/xc_firmware ilc_171_eth_2tx_firmware ilc_191_eth_2tx_firmware ilc_191_me\/an_firmware axc_1050_fir…
|
Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive information or make changes, as demonstrated by using the Create Backup feature to …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-9201
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211840
|
8.8 |
HIGH
Network
|
freedesktop debian canonical
|
poppler debian_linux ubuntu_linux
|
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It al…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-9200
|
2024-11-21 13:51 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|