|
219341
|
5.5 |
MEDIUM
Local
|
upx_project
|
upx
|
p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-20805
|
2024-11-21 13:39 |
2020-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219342
|
5.3 |
MEDIUM
Local
|
vim debian opensuse canonical apple starwindsoftware
|
vim debian_linux leap ubuntu_linux mac_os_x command_center san_\&_nas
|
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
|
CWE-78
OS Command
|
CVE-2019-20807
|
2024-11-21 13:39 |
2020-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219343
|
4.4 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20806
|
2024-11-21 13:39 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219344
|
8.8 |
HIGH
Network
|
gilacms
|
gila_cms
|
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
|
CWE-352
Origin Validation Error
|
CVE-2019-20804
|
2024-11-21 13:39 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219345
|
6.1 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_preview_theme.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20803
|
2024-11-21 13:39 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219346
|
6.1 |
MEDIUM
Network
|
readdle
|
documents
|
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server improperly displays directory names, leading to Stored XSS, which may be used to …
|
CWE-79
Cross-site Scripting
|
CVE-2019-20802
|
2024-11-21 13:39 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219347
|
5.3 |
MEDIUM
Network
|
readdle
|
documents
|
An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks …
|
CWE-862 CWE-863
Missing Authorization Incorrect Authorization
|
CVE-2019-20801
|
2024-11-21 13:39 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219348
|
9.8 |
CRITICAL
Network
|
cherokee-project
|
cherokee
|
In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in handler_cgi.c by sending many request headers, as demonstrated by a GET reques…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20800
|
2024-11-21 13:39 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219349
|
7.5 |
HIGH
Network
|
cherokee-project
|
cherokee
|
In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work of a server.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20799
|
2024-11-21 13:39 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219350
|
8.4 |
HIGH
Network
|
cherokee-project
|
cherokee
|
An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displayed on the About page in the default configuration of the web server and its ad…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20798
|
2024-11-21 13:39 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|