|
222241
|
6.1 |
MEDIUM
Network
|
sakailms
|
sakai
|
Sakai through 12.6 allows XSS via a chat user name.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16148
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222242
|
4.8 |
MEDIUM
Network
|
getgophish
|
gophish
|
Gophish through 0.8.0 allows XSS via a username.
|
CWE-79
Cross-site Scripting
|
CVE-2019-16146
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222243
|
9.8 |
CRITICAL
Network
|
atutor
|
atutor
|
In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next, he can change the …
|
CWE-863
Incorrect Authorization
|
CVE-2019-16114
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222244
|
7.5 |
HIGH
Network
|
generator-rs_project
|
generator-rs
|
An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-16144
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222245
|
9.8 |
CRITICAL
Network
|
blake2
|
blake2-rust
|
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-16143
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222246
|
9.8 |
CRITICAL
Network
|
renderdocs-rs_project
|
renderdocs-rs
|
An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application.
|
CWE-20
Improper Input Validation
|
CVE-2019-16142
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222247
|
7.5 |
HIGH
Network
|
once_cell_project
|
once_cell
|
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
|
CWE-20
Improper Input Validation
|
CVE-2019-16141
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222248
|
9.8 |
CRITICAL
Network
|
isahc_project
|
isahc
|
An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion.
|
CWE-416
Use After Free
|
CVE-2019-16140
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222249
|
9.8 |
CRITICAL
Network
|
compact_arena_project
|
compact_arena
|
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2019-16139
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222250
|
9.8 |
CRITICAL
Network
|
image-rs
|
image
|
An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len is called on an uninitialized vector, leading to a use-after-free and arbitrary…
|
CWE-416
Use After Free
|
CVE-2019-16138
|
2024-11-21 13:30 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|