|
221971
|
6.5 |
MEDIUM
Network
|
djangoproject fedoraproject
|
django fedora
|
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but ed…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19118
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221972
|
9.8 |
CRITICAL
Network
|
freeswitch
|
freeswitch
|
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-19492
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221973
|
6.1 |
MEDIUM
Network
|
testlink
|
testlink
|
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19491
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221974
|
7.3 |
HIGH
Local
|
litemanager
|
litemanager
|
LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by ROMFUSClient.exe.
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-19490
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221975
|
5.5 |
MEDIUM
Local
|
smplayer
|
smplayer
|
SMPlayer 19.5.0 has a buffer overflow via a long .m3u file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19489
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221976
|
4.6 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-cac1.c mishandles buffer limits for CAC certificates.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-19481
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221977
|
4.6 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry.
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2019-19480
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221978
|
5.5 |
MEDIUM
Local
|
opensc_project debian fedoraproject
|
opensc debian_linux fedora
|
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19479
|
2024-11-21 13:34 |
2019-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221979
|
8.8 |
HIGH
Network
|
zmanda
|
amanda
|
In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak defau…
|
CWE-352 CWE-78
Origin Validation Error OS Command
|
CVE-2019-19469
|
2024-11-21 13:34 |
2019-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221980
|
4.9 |
MEDIUM
Network
|
proftpd fedoraproject debian
|
proftpd fedora debian_linux
|
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encounter…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19269
|
2024-11-21 13:34 |
2019-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|