|
222141
|
5.5 |
MEDIUM
Local
|
beego
|
beego
|
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16355
|
2024-11-21 13:30 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222142
|
4.7 |
MEDIUM
Local
|
beego
|
beego
|
The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file creation within a directory with weak permissions.
|
CWE-362 CWE-732
Race Condition Incorrect Permission Assignment for Critical Resource
|
CVE-2019-16354
|
2024-11-21 13:30 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222143
|
7.5 |
HIGH
Network
|
geautomation
|
proficy
|
Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic from a remote device, as demonstrated by an RX7i device.
|
NVD-CWE-noinfo
|
CVE-2019-16353
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222144
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-16352
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222145
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16351
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222146
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16350
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222147
|
5.5 |
MEDIUM
Local
|
axiosys
|
bento4
|
Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16349
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222148
|
6.5 |
MEDIUM
Network
|
libwav_project
|
libwav
|
marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-16348
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222149
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16347
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222150
|
8.8 |
HIGH
Network
|
miniupnp_project
|
ngiflib
|
ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinterlacing for small pictures is mishandled.
|
CWE-787 CWE-682
Out-of-bounds Write Incorrect Calculation
|
CVE-2019-16346
|
2024-11-21 13:30 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|