|
221931
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_501_firmware
|
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-18203
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221932
|
9.8 |
CRITICAL
Network
|
gnu
|
libidn2
|
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18224
|
2024-11-21 13:32 |
2019-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221933
|
7.8 |
HIGH
Local
|
file_project debian opensuse netapp fedoraproject canonical
|
file debian_linux leap active_iq_unified_manager fedora ubuntu_linux
|
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18218
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221934
|
7.5 |
HIGH
Network
|
proftpd
|
proftpd
|
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinit…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18217
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221935
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17409
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221936
|
6.8 |
MEDIUM
Physics
|
asus
|
rog_zephyrus_m_gm501gs_firmware
|
The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in whi…
|
NVD-CWE-noinfo
|
CVE-2019-18216
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221937
|
7.7 |
HIGH
Network
|
video_converter_project
|
video_converter
|
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The worklo…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-18214
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221938
|
6.1 |
MEDIUM
Network
|
etherpad
|
etherpad
|
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18209
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221939
|
5.3 |
MEDIUM
Network
|
wago
|
pfc_firmware
|
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via craft…
|
NVD-CWE-noinfo
|
CVE-2019-18202
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221940
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag,…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-18198
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|