|
223321
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) o…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-12881
|
2024-11-21 13:23 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223322
|
6.1 |
MEDIUM
Network
|
evernote
|
web_clipper
|
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any …
|
CWE-79
Cross-site Scripting
|
CVE-2019-12592
|
2024-11-21 13:23 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223323
|
6.5 |
MEDIUM
Network
|
alpinelinux
|
abuild
|
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
|
CWE-668 CWE-862
Exposure of Resource to Wrong Sphere Missing Authorization
|
CVE-2019-12875
|
2024-11-21 13:23 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223324
|
9.8 |
CRITICAL
Network
|
videolan
|
vlc_media_player
|
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a dou…
|
CWE-415
Double Free
|
CVE-2019-12874
|
2024-11-21 13:23 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223325
|
7.2 |
HIGH
Network
|
dotcms
|
dotcms
|
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.
|
CWE-89
SQL Injection
|
CVE-2019-12872
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223326
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12823
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223327
|
7.2 |
HIGH
Network
|
misp
|
misp
|
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deser…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-12868
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223328
|
5.5 |
MEDIUM
Local
|
radare
|
radare2
|
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
|
CWE-415
Double Free
|
CVE-2019-12865
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223329
|
6.1 |
MEDIUM
Network
|
seeddms
|
seeddms
|
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Name.
|
CWE-79
Cross-site Scripting
|
CVE-2019-12801
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223330
|
9.8 |
CRITICAL
Network
|
wago
|
852-303_firmware 852-1305_firmware 852-1505_firmware
|
WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords that can be used to login via SSH and TELNET.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-12550
|
2024-11-21 13:23 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|