|
224801
|
9.1 |
CRITICAL
Network
|
stb_project
|
stb
|
stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15058
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224802
|
9.8 |
CRITICAL
Network
|
gradle
|
gradle
|
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subs…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-15052
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224803
|
6.8 |
MEDIUM
Network
|
atlassian
|
html_include_and_replace_macro
|
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15053
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224804
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15050
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224805
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15049
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224806
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-15048
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224807
|
8.8 |
HIGH
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-15047
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224808
|
6.1 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-14974
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224809
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
|
CWE-287
Improper Authentication
|
CVE-2019-15046
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224810
|
9.8 |
CRITICAL
Network
|
ninjaforms
|
ninjaforms
|
The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.
|
CWE-89
SQL Injection
|
CVE-2019-15025
|
2024-11-21 13:27 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|