|
212331
|
7.5 |
HIGH
Network
|
seafile
|
seadroid
|
The seadroid (aka Seafile Android Client) application through 2.2.13 for Android always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-8919
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212332
|
9.8 |
CRITICAL
Network
|
solarwinds
|
orion_network_performance_monitor
|
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unau…
|
NVD-CWE-noinfo
|
CVE-2019-8917
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212333
|
7.8 |
HIGH
Local
|
linux redhat canonical opensuse
|
linux_kernel enterprise_linux ubuntu_linux leap
|
In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
|
CWE-416
Use After Free
|
CVE-2019-8912
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212334
|
6.1 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
|
CWE-79
Cross-site Scripting
|
CVE-2019-8911
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212335
|
8.8 |
HIGH
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-8910
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212336
|
7.5 |
HIGH
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-8909
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212337
|
9.8 |
CRITICAL
Network
|
wtcms_project
|
wtcms
|
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading …
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2019-8908
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212338
|
8.8 |
HIGH
Network
|
file_project debian opensuse canonical
|
file debian_linux leap ubuntu_linux
|
do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-8907
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212339
|
4.4 |
MEDIUM
Local
|
file_project canonical opensuse apple
|
file ubuntu_linux leap mac_os_x iphone_os watchos tvos
|
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8906
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212340
|
4.4 |
MEDIUM
Local
|
debian file_project canonical opensuse
|
debian_linux file ubuntu_linux leap
|
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-8905
|
2024-11-21 13:50 |
2019-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|