|
222131
|
6.5 |
MEDIUM
Network
|
mz-automation
|
libiec61850
|
In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-19930
|
2024-11-21 13:35 |
2019-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222132
|
7.8 |
HIGH
Local
|
malwarebytes
|
adwcleaner
|
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.
|
CWE-426
Untrusted Search Path
|
CVE-2019-19929
|
2024-11-21 13:35 |
2019-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222133
|
7.5 |
HIGH
Network
|
sqlite siemens oracle debian redhat opensuse suse netapp
|
sqlite sinec_infrastructure_network_services mysql_workbench debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap backports_sle p…
|
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplet…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19926
|
2024-11-21 13:35 |
2019-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222134
|
5.5 |
MEDIUM
Local
|
linux debian canonical oracle netapp
|
linux_kernel debian_linux ubuntu_linux sd-wan_edge cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire_\&_hci_management_node active_iq_u…
|
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by genera…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-19922
|
2024-11-21 13:35 |
2019-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222135
|
8.8 |
HIGH
Network
|
sa-exim_project debian canonical
|
sa-exim debian_linux ubuntu_linux
|
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint …
|
CWE-78
OS Command
|
CVE-2019-19920
|
2024-11-21 13:35 |
2019-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222136
|
9.8 |
CRITICAL
Network
|
handlebars.js_project tenable
|
handlebars.js tenable.sc
|
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allo…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2019-19919
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222137
|
7.8 |
HIGH
Local
|
lout_project opensuse fedoraproject
|
lout leap fedora backports_sle
|
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19918
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222138
|
7.8 |
HIGH
Local
|
lout_project opensuse fedoraproject
|
lout leap backports_sle fedora
|
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19917
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222139
|
9.8 |
CRITICAL
Network
|
neuvector
|
neuvector
|
NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any va…
|
CWE-521
Weak Password Requirements
|
CVE-2019-19747
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222140
|
6.1 |
MEDIUM
Network
|
midori-browser
|
midori
|
In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19916
|
2024-11-21 13:35 |
2019-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|