|
213611
|
9.4 |
CRITICAL
Network
|
logonbox
|
nervepoint_access_manager
|
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usern…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-6716
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213612
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must vi…
|
CWE-416
Use After Free
|
CVE-2019-6730
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213613
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must vi…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6729
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213614
|
6.5 |
MEDIUM
Network
|
foxitsoftware
|
phantompdf reader
|
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6728
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213615
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must vi…
|
CWE-416
Use After Free
|
CVE-2019-6727
|
2024-11-21 13:47 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213616
|
7.5 |
HIGH
Network
|
imagemagick opensuse debian canonical
|
imagemagick leap debian_linux ubuntu_linux
|
In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-7175
|
2024-11-21 13:47 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213617
|
5.5 |
MEDIUM
Local
|
avaya
|
one-x_communicator
|
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-7006
|
2024-11-21 13:47 |
2019-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213618
|
9.8 |
CRITICAL
Network
|
sqlalchemy debian opensuse redhat oracle
|
sqlalchemy debian_linux leap backports_sle enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux communications_operations_monitor
|
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
|
CWE-89
SQL Injection
|
CVE-2019-7164
|
2024-11-21 13:47 |
2019-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213619
|
8.1 |
HIGH
Network
|
linux debian canonical f5 redhat
|
linux_kernel debian_linux ubuntu_linux big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy…
|
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-6974
|
2024-11-21 13:47 |
2019-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213620
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject
|
django ubuntu_linux fedora
|
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() func…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6975
|
2024-11-21 13:47 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|