|
222071
|
7.5 |
HIGH
Network
|
vino_project
|
vino
|
tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.
|
NVD-CWE-noinfo
|
CVE-2019-17414
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222072
|
8.8 |
HIGH
Network
|
citrix
|
application_delivery_management
|
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
|
NVD-CWE-noinfo
|
CVE-2019-17366
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222073
|
7.8 |
HIGH
Local
|
nixos
|
nix
|
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17365
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222074
|
6.5 |
MEDIUM
Network
|
exiv2 debian canonical
|
exiv2 debian_linux ubuntu_linux
|
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17402
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222075
|
3.3 |
LOW
Local
|
liblnk_project
|
liblnk
|
libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue th…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-17401
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222076
|
9.8 |
CRITICAL
Network
|
joomlashack
|
shack_forms_pro
|
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
|
CWE-22
Path Traversal
|
CVE-2019-17399
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222077
|
7.5 |
HIGH
Network
|
riot-os
|
riot
|
In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP socket. The receive loop ends. This allows an attacker (via a large packet) to prev…
|
NVD-CWE-noinfo
|
CVE-2019-17389
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222078
|
6.1 |
MEDIUM
Network
|
eleopard
|
animate_it\!
|
The animate-it plugin before 2.3.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17385
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222079
|
6.1 |
MEDIUM
Network
|
eleopard
|
animate_it\!
|
The animate-it plugin before 2.3.4 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17384
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222080
|
9.8 |
CRITICAL
Network
|
netaddr_project
|
netaddr
|
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17383
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|