|
222161
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000258c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17246
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222162
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x0000000000004359.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17245
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222163
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000001d8a.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17244
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222164
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000003155.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17243
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222165
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000966f.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17242
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222166
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000d563.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17241
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222167
|
6.1 |
MEDIUM
Network
|
etoilewebdesign
|
ultimate_faq
|
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17233
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222168
|
7.5 |
HIGH
Network
|
etoilewebdesign
|
ultimate_faq
|
Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-17232
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222169
|
6.1 |
MEDIUM
Network
|
wpfactory
|
download_plugins_and_themes_from_dashboard
|
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17239
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222170
|
7.8 |
HIGH
Local
|
pcprotect
|
antivirus
|
PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the director…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16913
|
2024-11-21 13:31 |
2019-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|