|
223131
|
9.8 |
CRITICAL
Network
|
supermicro
|
superdoctor_5
|
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13131
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223132
|
7.5 |
HIGH
Network
|
motorola
|
cx2l_mwr04l_firmware
|
On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handli…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-13129
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223133
|
8.8 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway …
|
CWE-78
OS Command
|
CVE-2019-13128
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223134
|
6.1 |
MEDIUM
Network
|
draw jgraph
|
draw.io_diagrams mxgraph
|
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field lea…
|
CWE-79 CWE-20
Cross-site Scripting Improper Input Validation
|
CVE-2019-13127
|
2024-11-21 13:24 |
2019-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223135
|
7.8 |
HIGH
Local
|
tencent
|
habomalhunter
|
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2019-13125
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223136
|
5.3 |
MEDIUM
Network
|
xmlsoft opensuse netapp oracle fedoraproject canonical apple
|
libxslt leap cloud_backup steelstore_cloud_integrated_storage oncommand_workflow_automation oncommand_insight ontap_select_deploy_administration_utility clustered_data_ontap e…
|
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, …
|
CWE-843
Type Confusion
|
CVE-2019-13118
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223137
|
5.3 |
MEDIUM
Network
|
xmlsoft debian canonical fedoraproject opensuse oracle
|
libxslt debian_linux ubuntu_linux fedora leap openjdk
|
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte o…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-13117
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223138
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject debian canonical
|
exiv2 fedora debian_linux ubuntu_linux
|
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13114
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223139
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject canonical
|
exiv2 fedora ubuntu_linux
|
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
|
CWE-617
Reachable Assertion
|
CVE-2019-13113
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223140
|
6.5 |
MEDIUM
Network
|
exiv2 fedoraproject canonical debian
|
exiv2 fedora ubuntu_linux debian_linux
|
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-13112
|
2024-11-21 13:24 |
2019-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|