|
222401
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-18797
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222402
|
8.8 |
HIGH
Network
|
rakuten
|
viber
|
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on por…
|
CWE-311 CWE-319
Missing Encryption of Sensitive Data Cleartext Transmission of Sensitive Information
|
CVE-2019-18800
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222403
|
5.5 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-18786
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222404
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-18784
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222405
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.
|
CWE-862
Missing Authorization
|
CVE-2019-18674
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222406
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2019-18650
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222407
|
9.8 |
CRITICAL
Network
|
veritas
|
infoscale flex_appliance access access_appliance cluster_server storage_foundation_ha
|
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. The…
|
CWE-77
Command Injection
|
CVE-2019-18780
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222408
|
7.8 |
HIGH
Local
|
centrify
|
authentication_service privilege_elevation_service
|
The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecif…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-18631
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222409
|
9.8 |
CRITICAL
Network
|
isl
|
arp-guard
|
A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-18663
|
2024-11-21 13:33 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222410
|
7.0 |
HIGH
Local
|
sudo_project
|
sudo
|
Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and t…
|
CWE-362
Race Condition
|
CVE-2019-18684
|
2024-11-21 13:33 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|