|
220951
|
6.5 |
MEDIUM
Network
|
yaml-cpp_project
|
yaml-cpp
|
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML …
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-6285
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220952
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6284
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220953
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6283
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220954
|
5.4 |
MEDIUM
Network
|
jpress
|
jpress
|
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6278
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220955
|
9.8 |
CRITICAL
Network
|
icmsdev
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6259
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220956
|
7.7 |
HIGH
Network
|
std42
|
elfinder
|
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-6257
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220957
|
8.1 |
HIGH
Network
|
gnome wpewebkit webkitgtk fedoraproject canonical opensuse
|
epiphany wpe_webkit webkitgtk fedora ubuntu_linux leap
|
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a…
|
NVD-CWE-noinfo
|
CVE-2019-6251
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220958
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.
|
CWE-352
Origin Validation Error
|
CVE-2019-6249
|
2024-11-21 13:46 |
2019-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220959
|
6.1 |
MEDIUM
Network
|
citysearch_\/_hotfrog_\/_gelbeseiten_clone_script_project
|
citysearch_\/_hotfrog_\/_gelbeseiten_clone_script
|
PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demonstrated by restaurants-details.php.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6248
|
2024-11-21 13:46 |
2019-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220960
|
8.8 |
HIGH
Network
|
svgpp antigrain
|
svgpp agg
|
An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the render_scanlines_a…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6247
|
2024-11-21 13:46 |
2019-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|