|
222211
|
9.8 |
CRITICAL
Network
|
openmpt
|
libopenmpt
|
In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API,…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17113
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222212
|
6.1 |
MEDIUM
Network
|
themeisle
|
visualizer
|
A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute arbitrary JavaScript when an admin or other privileged user edits the chart via t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16931
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222213
|
7.5 |
HIGH
Network
|
nlnetlabs canonical
|
unbound ubuntu_linux
|
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
|
CWE-755 CWE-908
Improper Handling of Exceptional Conditions Use of Uninitialized Resource
|
CVE-2019-16866
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222214
|
7.8 |
HIGH
Local
|
linuxmint
|
mintinstall
|
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17080
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222215
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The cxgb4 driver is directly calling dma_map_single (a DMA function) from a stack va…
|
NVD-CWE-noinfo
|
CVE-2019-17075
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222216
|
5.4 |
MEDIUM
Network
|
xunruicms
|
xunruicms
|
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17074
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222217
|
6.5 |
MEDIUM
Network
|
emlog
|
emlog
|
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-17073
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222218
|
6.1 |
MEDIUM
Network
|
eclipse oracle
|
mojarra mojarra_javaserver_faces retail_service_backbone retail_integration_bus retail_merchandising_system application_testing_suite secure_global_desktop retail_financial_integ…
|
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client windo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17091
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222219
|
7.5 |
HIGH
Network
|
putty opensuse netapp
|
putty leap oncommand_unified_manager_core_package
|
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
|
CWE-416
Use After Free
|
CVE-2019-17069
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222220
|
7.5 |
HIGH
Network
|
putty opensuse
|
putty leap
|
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
|
CWE-74
Injection
|
CVE-2019-17068
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|