|
212141
|
9.1 |
CRITICAL
Network
|
mopcms
|
mopcms
|
A Path Traversal vulnerability was discovered in MOPCMS through 2018-11-30, leading to deletion of unexpected critical files. The exploitation point is in the "column management" function. The path a…
|
CWE-22
Path Traversal
|
CVE-2019-9015
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212142
|
7.5 |
HIGH
Network
|
eclipse
|
wakaama
|
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-9004
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212143
|
7.5 |
HIGH
Network
|
linux netapp canonical opensuse
|
linux_kernel solidfire hci_management_node snapprotect cn1610_firmware ubuntu_linux leap
|
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by …
|
CWE-416
Use After Free
|
CVE-2019-9003
|
2024-11-21 13:50 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212144
|
9.8 |
CRITICAL
Network
|
tiny_issue_project pixeline
|
tiny_issue bugs
|
An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the ins…
|
CWE-862
Missing Authorization
|
CVE-2019-9002
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212145
|
7.5 |
HIGH
Network
|
torproject
|
tor
|
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-8955
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212146
|
9.8 |
CRITICAL
Network
|
signiant
|
manager\+agents
|
In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-8996
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212147
|
9.8 |
CRITICAL
Network
|
netis-systems
|
wf2411_firmware wf2880_firmware
|
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause de…
|
CWE-787 CWE-306
Out-of-bounds Write Missing Authentication for Critical Function
|
CVE-2019-8985
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212148
|
6.1 |
MEDIUM
Network
|
altn
|
mdaemon
|
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-8984
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212149
|
6.1 |
MEDIUM
Network
|
altn
|
mdaemon
|
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
|
CWE-79
Cross-site Scripting
|
CVE-2019-8983
|
2024-11-21 13:50 |
2019-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212150
|
9.6 |
CRITICAL
Network
|
wavemaker
|
wavemarker_studio
|
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-8982
|
2024-11-21 13:50 |
2019-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|