|
223091
|
7.8 |
HIGH
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a9601.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13246
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223092
|
7.8 |
HIGH
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a95b1.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13245
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223093
|
7.8 |
HIGH
Local
|
faststone
|
image_viewer
|
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x0000000000002d7d.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13244
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223094
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13243
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223095
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13242
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223096
|
7.8 |
HIGH
Local
|
flightcrew_project canonical
|
flightcrew ubuntu_linux
|
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
|
CWE-22
Path Traversal
|
CVE-2019-13241
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223097
|
6.1 |
MEDIUM
Network
|
glpi-project
|
glpi
|
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
|
CWE-79
Cross-site Scripting
|
CVE-2019-13239
|
2024-11-21 13:24 |
2019-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223098
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to crashes. When parsing input video, the program allocates a new buffer to parse …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-13238
|
2024-11-21 13:24 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223099
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX boun…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-13233
|
2024-11-21 13:24 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223100
|
3.3 |
LOW
Local
|
unzip_project debian
|
unzip debian_linux
|
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-13232
|
2024-11-21 13:24 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|