|
222191
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17203
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222192
|
7.5 |
HIGH
Network
|
webpagetest
|
webpagetest
|
www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of an unanchored regular expression, as demonstrated by the a.jpg\.. substring.
|
CWE-22
Path Traversal
|
CVE-2019-17199
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222193
|
9.8 |
CRITICAL
Network
|
open-emr
|
openemr
|
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
|
CWE-89
SQL Injection
|
CVE-2019-17197
|
2024-11-21 13:31 |
2019-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222194
|
9.8 |
CRITICAL
Network
|
signal
|
private_messenger
|
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easie…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-17192
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222195
|
7.5 |
HIGH
Network
|
signal
|
private_messenger
|
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is…
|
CWE-863
Incorrect Authorization
|
CVE-2019-17191
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222196
|
9.8 |
CRITICAL
Network
|
xerox
|
atlalink_firmware
|
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
|
NVD-CWE-noinfo
|
CVE-2019-17184
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222197
|
7.2 |
HIGH
Network
|
fecmall
|
fecmall
|
An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An attacker can bypass a front-end restriction and upload PHP code to the webserv…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-17188
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222198
|
7.5 |
HIGH
Network
|
python fedoraproject
|
pillow fedora
|
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of ti…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-16865
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222199
|
7.5 |
HIGH
Network
|
foxitsoftware
|
reader
|
Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-17183
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222200
|
7.8 |
HIGH
Local
|
valvesoftware
|
steam_client
|
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This …
|
CWE-22
Path Traversal
|
CVE-2019-17180
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|