|
223161
|
5.5 |
MEDIUM
Local
|
toaruos_project
|
toaruos
|
kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allocation patterns (involving PAGE_SIZE, and a value less than PAGE_SIZE).
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-13048
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223162
|
7.8 |
HIGH
Local
|
toaruos_project
|
toaruos
|
kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SETHEAP, allowing arbitrary kernel pages to be mapped into user land, leading to r…
|
CWE-862
Missing Authorization
|
CVE-2019-13047
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223163
|
7.8 |
HIGH
Local
|
toaruos_project
|
toaruos
|
linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications.
|
CWE-388
7PK - Errors
|
CVE-2019-13046
|
2024-11-21 13:24 |
2019-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223164
|
8.1 |
HIGH
Network
|
irssi
|
irssi
|
Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.
|
CWE-416
Use After Free
|
CVE-2019-13045
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223165
|
6.1 |
MEDIUM
Network
|
mod_auth_mellon_project oracle fedoraproject canonical
|
mod_auth_mellon zfs_storage_appliance_kit fedora ubuntu_linux
|
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
|
CWE-601
Open Redirect
|
CVE-2019-13038
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223166
|
7.8 |
HIGH
Local
|
pandorafms
|
pandora_fms
|
Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, t…
|
NVD-CWE-noinfo
|
CVE-2019-13035
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223167
|
5.5 |
MEDIUM
Local
|
flightcrew_project
|
flightcrew
|
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13032
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223168
|
8.1 |
HIGH
Network
|
lemonldap-ng debian
|
lemonldap\ debian_linux
|
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" r…
|
CWE-611
XXE
|
CVE-2019-13031
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223169
|
8.8 |
HIGH
Network
|
minv
|
electronic_identification_cards_client
|
An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or de…
|
CWE-284
Improper Access Control
|
CVE-2019-13028
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223170
|
7.5 |
HIGH
Network
|
gnome
|
glib
|
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kf…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-13012
|
2024-11-21 13:24 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|