|
222641
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2f…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19815
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222642
|
7.8 |
HIGH
Local
|
linux canonical debian netapp
|
linux_kernel ubuntu_linux debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager data_availability_services solidfire hci_management_node aff_a700s_firmwar…
|
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a va…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19816
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222643
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19814
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222644
|
5.5 |
MEDIUM
Local
|
linux canonical debian netapp
|
linux_kernel ubuntu_linux debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager data_availability_services solidfire hci_management_node aff_a700s_firmwar…
|
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/…
|
CWE-416
Use After Free
|
CVE-2019-19813
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222645
|
6.5 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
|
NVD-CWE-noinfo
|
CVE-2019-19830
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222646
|
9.8 |
CRITICAL
Network
|
drupal
|
views_dynamic_field
|
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involv…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-19826
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222647
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitro_free_pdf_reader
|
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19818
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222648
|
6.5 |
MEDIUM
Network
|
dlink
|
dir-615_t1_firmware
|
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
|
NVD-CWE-noinfo
|
CVE-2019-19743
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222649
|
7.5 |
HIGH
Network
|
roxyfileman
|
roxy_fileman
|
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by u…
|
CWE-22
Path Traversal
|
CVE-2019-19731
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222650
|
6.5 |
MEDIUM
Network
|
cyrus debian fedoraproject canonical
|
imap debian_linux fedora ubuntu_linux
|
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19783
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|