|
222071
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the …
|
CWE-416
Use After Free
|
CVE-2019-17142
|
2024-11-21 13:31 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222072
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the …
|
CWE-416
Use After Free
|
CVE-2019-17141
|
2024-11-21 13:31 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222073
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the …
|
CWE-416
Use After Free
|
CVE-2019-17140
|
2024-11-21 13:31 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222074
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17139
|
2024-11-21 13:31 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222075
|
4.3 |
MEDIUM
Network
|
foxitsoftware
|
foxit_studio_photo
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in t…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17138
|
2024-11-21 13:31 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222076
|
7.8 |
HIGH
Local
|
avg avast
|
anti-virus antivirus
|
An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-17093
|
2024-11-21 13:31 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222077
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16977
|
2024-11-21 13:31 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222078
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16975
|
2024-11-21 13:31 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222079
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16976
|
2024-11-21 13:31 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222080
|
6.1 |
MEDIUM
Network
|
fusionpbx
|
fusionpbx
|
In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16973
|
2024-11-21 13:31 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|