|
222201
|
9.8 |
CRITICAL
Network
|
telerik
|
radchart ui_for_asp.net_ajax
|
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server throu…
|
CWE-22
Path Traversal
|
CVE-2019-19790
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222202
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_eventlog_analyzer
|
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypa…
|
NVD-CWE-noinfo
|
CVE-2019-19774
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222203
|
5.3 |
MEDIUM
Network
|
dovecot fedoraproject
|
dovecot fedora
|
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group ad…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19722
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222204
|
7.8 |
HIGH
Local
|
atasm_project fedoraproject
|
atasm fedora
|
ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19787
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222205
|
7.8 |
HIGH
Local
|
atasm_project fedoraproject
|
atasm fedora
|
ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19786
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222206
|
7.8 |
HIGH
Local
|
atasm_project fedoraproject
|
atasm fedora
|
ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19785
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222207
|
9.8 |
CRITICAL
Network
|
labf
|
aceaxe_plus
|
The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19782
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222208
|
8.8 |
HIGH
Network
|
lodahs_project
|
lodahs
|
The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurren…
|
NVD-CWE-noinfo
|
CVE-2019-19771
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222209
|
8.2 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created …
|
CWE-416
Use After Free
|
CVE-2019-19770
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222210
|
6.7 |
MEDIUM
Local
|
linux fedoraproject
|
linux_kernel fedora
|
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).
|
CWE-416
Use After Free
|
CVE-2019-19769
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|