|
223611
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled informati…
|
CWE-352
Origin Validation Error
|
CVE-2019-18411
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223612
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18799
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223613
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18798
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223614
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-18797
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223615
|
8.8 |
HIGH
Network
|
rakuten
|
viber
|
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on por…
|
CWE-311 CWE-319
Missing Encryption of Sensitive Data Cleartext Transmission of Sensitive Information
|
CVE-2019-18800
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223616
|
5.5 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-18786
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223617
|
9.8 |
CRITICAL
Network
|
salesagility
|
suitecrm
|
SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-18784
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223618
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.
|
CWE-862
Missing Authorization
|
CVE-2019-18674
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223619
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2019-18650
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223620
|
9.8 |
CRITICAL
Network
|
veritas
|
infoscale flex_appliance access access_appliance cluster_server storage_foundation_ha
|
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. The…
|
CWE-77
Command Injection
|
CVE-2019-18780
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|