|
222701
|
9.8 |
CRITICAL
Network
|
ohdsi
|
webapi
|
Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.
|
CWE-89
SQL Injection
|
CVE-2019-15563
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222702
|
9.8 |
CRITICAL
Network
|
servo
|
smallvec
|
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15554
|
2024-11-21 13:29 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222703
|
9.8 |
CRITICAL
Network
|
gorm
|
gorm
|
GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input where Gorm expects trusted SQL fragments is a vulnerability in the application,…
|
CWE-89
SQL Injection
|
CVE-2019-15562
|
2024-11-21 13:29 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222704
|
9.8 |
CRITICAL
Network
|
flashlingo_project
|
flashlingo
|
FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
|
CWE-89
SQL Injection
|
CVE-2019-15561
|
2024-11-21 13:29 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222705
|
9.8 |
CRITICAL
Network
|
social_network_project
|
social_network
|
Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
|
CWE-89
SQL Injection
|
CVE-2019-15556
|
2024-11-21 13:29 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222706
|
9.1 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15167
|
2024-11-21 13:28 |
2022-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222707
|
5.3 |
MEDIUM
Network
|
linbit debian
|
csync2 debian_linux
|
An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this fun…
|
CWE-252
Unchecked Return Value
|
CVE-2019-15523
|
2024-11-21 13:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222708
|
7.5 |
HIGH
Network
|
morph_project
|
morph
|
An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo in the constructor of the Owned contract (which is inherited by MORPH Token) a…
|
NVD-CWE-noinfo
|
CVE-2019-15080
|
2024-11-21 13:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222709
|
7.5 |
HIGH
Network
|
eai_project
|
eai
|
A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This vulnerability could be used by an attacker to acquire EAI tokens for free.
|
NVD-CWE-noinfo
|
CVE-2019-15079
|
2024-11-21 13:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222710
|
7.5 |
HIGH
Network
|
xbornid
|
xbornid
|
An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The name of the constructor has a typo (wrong case: XBornID versus XBORNID) that al…
|
NVD-CWE-noinfo
|
CVE-2019-15078
|
2024-11-21 13:28 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|