|
219481
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira_server jira_data_center
|
The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authenticated remote attackers to view release version information in projects that they…
|
CWE-862
Missing Authorization
|
CVE-2019-20407
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219482
|
4.9 |
MEDIUM
Network
|
atlassian
|
application_links
|
The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 before version 6.0.12, from version 6.1.0 before version 6.1.2, from version 7.0.0 …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-20105
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219483
|
7.8 |
HIGH
Local
|
gnome linuxmint debian
|
gthumb pix debian_linux
|
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20326
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219484
|
7.5 |
HIGH
Network
|
sync
|
oxygen_xml_editor oxygen_xml_author oxygen_xml_developer
|
Oxygen XML Editor 21.1.1 allows XXE to read any file.
|
CWE-611
XXE
|
CVE-2019-20191
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219485
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508).
|
NVD-CWE-noinfo
|
CVE-2019-20491
|
2024-11-21 13:38 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219486
|
9.8 |
CRITICAL
Network
|
quest
|
kace_systems_management
|
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
|
CWE-78
OS Command
|
CVE-2019-20504
|
2024-11-21 13:38 |
2020-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219487
|
6.5 |
MEDIUM
Network
|
usrsctp_project debian canonical
|
usrsctp debian_linux ubuntu_linux
|
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20503
|
2024-11-21 13:38 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219488
|
7.5 |
HIGH
Network
|
echatserver
|
easy_chat_server
|
An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-20502
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219489
|
3.5 |
LOW
Adjacent
|
qemu opensuse debian canonical
|
qemu leap debian_linux ubuntu_linux
|
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is n…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-20382
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219490
|
7.8 |
HIGH
Local
|
dlink
|
dwl-2600ap_firmware
|
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.…
|
CWE-78
OS Command
|
CVE-2019-20501
|
2024-11-21 13:38 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|