|
223891
|
7.5 |
HIGH
Network
|
altn
|
mdaemon_email_server
|
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably incons…
|
CWE-20
Improper Input Validation
|
CVE-2019-13612
|
2024-11-21 13:25 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223892
|
8.8 |
HIGH
Network
|
python-engineio_project
|
python-engineio
|
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a vi…
|
CWE-352
Origin Validation Error
|
CVE-2019-13611
|
2024-11-21 13:25 |
2019-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223893
|
5.9 |
MEDIUM
Network
|
assaabloy
|
hid_digitalpersona_4500_firmware
|
There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24. The key for obfuscating the fingerprint image is vulnerable to brute-force a…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-13604
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223894
|
7.8 |
HIGH
Local
|
videolan debian canonical opensuse
|
vlc_media_player debian_linux ubuntu_linux leap backports_sle
|
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow a…
|
CWE-787 CWE-191
Out-of-bounds Write Integer Underflow (Wrap or Wraparound)
|
CVE-2019-13602
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223895
|
9.8 |
CRITICAL
Network
|
getvera
|
vera_edge_firmware
|
LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via the code parameter to /port_3480/data_request because the "No unsafe lua allowed…
|
CWE-78
OS Command
|
CVE-2019-13598
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223896
|
9.8 |
CRITICAL
Network
|
sahipro
|
sahi_pro
|
_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can create a new script with an editor. It is possib…
|
CWE-78
OS Command
|
CVE-2019-13597
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223897
|
8.8 |
HIGH
Network
|
mirumee
|
saleor
|
In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.
|
CWE-352
Origin Validation Error
|
CVE-2019-13594
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223898
|
5.5 |
MEDIUM
Local
|
sound_exchange_project
|
sound_exchange
|
An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro th…
|
CWE-190 CWE-476
Integer Overflow or Wraparound NULL Pointer Dereference
|
CVE-2019-13590
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223899
|
9.8 |
CRITICAL
Network
|
anjlab
|
paranoid2
|
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2019-13589
|
2024-11-21 13:25 |
2019-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223900
|
8.8 |
HIGH
Network
|
zoom
|
zoom
|
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zo…
|
CWE-78
OS Command
|
CVE-2019-13567
|
2024-11-21 13:25 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|