|
223481
|
8.8 |
HIGH
Network
|
adplug_project fedoraproject
|
adplug fedora
|
AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14691
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223482
|
8.8 |
HIGH
Network
|
adplug_project fedoraproject
|
adplug fedora
|
AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14690
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223483
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14672
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223484
|
3.3 |
LOW
Local
|
firefly-iii
|
firefly_iii
|
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fint…
|
CWE-20
Improper Input Validation
|
CVE-2019-14671
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223485
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14670
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223486
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account sta…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14669
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223487
|
5.4 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transac…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14668
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223488
|
6.1 |
MEDIUM
Network
|
firefly-iii
|
firefly_iii
|
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript co…
|
CWE-79
Cross-site Scripting
|
CVE-2019-14667
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223489
|
6.5 |
MEDIUM
Network
|
enigmail fedoraproject
|
enigmail fedora
|
In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASC…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-14664
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223490
|
5.5 |
MEDIUM
Local
|
brandy_project
|
brandy
|
Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-14665
|
2024-11-21 13:27 |
2019-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|