|
222031
|
7.8 |
HIGH
Local
|
shibboleth
|
service_provider
|
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the u…
|
CWE-59
Link Following
|
CVE-2019-19191
|
2024-11-21 13:34 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222032
|
9.8 |
CRITICAL
Network
|
jalios
|
jcms
|
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-19033
|
2024-11-21 13:34 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222033
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19037
|
2024-11-21 13:34 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222034
|
5.5 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-19039
|
2024-11-21 13:34 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222035
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_dereference(root->node) can be zero.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19036
|
2024-11-21 13:34 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222036
|
3.3 |
LOW
Local
|
gnu canonical fedoraproject debian
|
glibc ubuntu_linux fedora debian_linux
|
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing …
|
CWE-665
Improper Initialization
|
CVE-2019-19126
|
2024-11-21 13:34 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222037
|
8.8 |
HIGH
Network
|
phicomm
|
k2\(psg1218\)_firmware
|
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci aut…
|
CWE-78
OS Command
|
CVE-2019-19117
|
2024-11-21 13:34 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222038
|
9.8 |
CRITICAL
Network
|
newbee-mall_project
|
newbee-mall
|
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-19113
|
2024-11-21 13:34 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222039
|
5.4 |
MEDIUM
Network
|
octopus
|
server
|
A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19085
|
2024-11-21 13:34 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222040
|
4.3 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underl…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-19084
|
2024-11-21 13:34 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|