|
221921
|
4.3 |
MEDIUM
Network
|
qt debian
|
qtbase debian_linux
|
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-18281
|
2024-11-21 13:32 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221922
|
8.8 |
HIGH
Network
|
online_grading_system_project
|
online_grading_system
|
Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into exe…
|
CWE-352
Origin Validation Error
|
CVE-2019-18280
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221923
|
7.8 |
HIGH
Local
|
videolan
|
vlc_media_player
|
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the …
|
NVD-CWE-noinfo
|
CVE-2019-18278
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221924
|
8.8 |
HIGH
Network
|
sitemagic
|
sitemagic
|
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via s…
|
CWE-352
Origin Validation Error
|
CVE-2019-18220
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221925
|
7.5 |
HIGH
Network
|
haproxy
|
haproxy
|
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if co…
|
CWE-444
HTTP Request Smuggling
|
CVE-2019-18277
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221926
|
6.1 |
MEDIUM
Network
|
sitemagic
|
sitemagic
|
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection with…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18219
|
2024-11-21 13:32 |
2019-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221927
|
7.8 |
HIGH
Local
|
nipper-ng_project
|
nipper-ng
|
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17424
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221928
|
7.5 |
HIGH
Network
|
universal_office_converter_project
|
universal_office_converter
|
The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-17400
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221929
|
8.1 |
HIGH
Network
|
libssh2 fedoraproject opensuse debian netapp
|
libssh2 fedora leap debian_linux element_software ontap_select_deploy_administration_utility solidfire hci_management_node active_iq_unified_manager bootstrap_os
|
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a s…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-17498
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221930
|
9.8 |
CRITICAL
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware
|
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 bef…
|
NVD-CWE-noinfo
|
CVE-2019-18225
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|