|
223351
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2019-12765
|
2024-11-21 13:23 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223352
|
6.5 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
|
NVD-CWE-noinfo
|
CVE-2019-12764
|
2024-11-21 13:23 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223353
|
6.6 |
MEDIUM
Network
|
misp
|
misp
|
An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admins have the inherent ability to reset passwords for all of their organization's …
|
CWE-269
Improper Privilege Management
|
CVE-2019-12794
|
2024-11-21 13:23 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223354
|
7.1 |
HIGH
Local
|
freedesktop canonical
|
dbus ubuntu_linux
|
dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubuntu 14.04 (and in some, less common, uses of dbus-daemon), allows cookie spoofi…
|
CWE-59
Link Following
|
CVE-2019-12749
|
2024-11-21 13:23 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223355
|
7.8 |
HIGH
Local
|
radare
|
radare2
|
In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. This allows remote attackers to cause a denial of service (application crash) or p…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-12790
|
2024-11-21 13:23 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223356
|
7.8 |
HIGH
Local
|
photodex
|
proshow_producer
|
An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges). It is possible to perform a buffer overflow via a crafted file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-12788
|
2024-11-21 13:23 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223357
|
8.8 |
HIGH
Network
|
dlink
|
dir-818lw_firmware
|
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.
|
CWE-78
OS Command
|
CVE-2019-12787
|
2024-11-21 13:23 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223358
|
8.8 |
HIGH
Network
|
dlink
|
dir-818lw_firmware
|
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
|
CWE-77
Command Injection
|
CVE-2019-12786
|
2024-11-21 13:23 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223359
|
9.8 |
CRITICAL
Network
|
belkin
|
crock-pot_smart_slow_cooker_with_wemo_firmware
|
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allo…
|
CWE-78
OS Command
|
CVE-2019-12780
|
2024-11-21 13:23 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223360
|
7.1 |
HIGH
Local
|
clusterlabs
|
libqb
|
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.
|
CWE-59
Link Following
|
CVE-2019-12779
|
2024-11-21 13:23 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|