|
221921
|
6.1 |
MEDIUM
Network
|
sceditor
|
sceditor
|
SCEditor 2.1.3 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19466
|
2024-11-21 13:34 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221922
|
9.8 |
CRITICAL
Network
|
sqlite netapp oracle siemens
|
sqlite cloud_backup ontap_select_deploy_administration_utility mysql_workbench sinec_infrastructure_network_services
|
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other …
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2019-19317
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221923
|
7.5 |
HIGH
Network
|
wireshark opensuse oracle debian
|
wireshark leap solaris zfs_storage_appliance debian_linux
|
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NU…
|
CWE-909
Missing Initialization of Resource
|
CVE-2019-19553
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221924
|
7.8 |
HIGH
Local
|
openbsd
|
openbsd
|
OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-19522
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221925
|
9.8 |
CRITICAL
Network
|
openbsd
|
openbsd
|
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and logi…
|
CWE-287
Improper Authentication
|
CVE-2019-19521
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221926
|
7.8 |
HIGH
Local
|
openbsd
|
openbsd
|
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlope…
|
CWE-863
Incorrect Authorization
|
CVE-2019-19520
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221927
|
7.8 |
HIGH
Local
|
openbsd
|
openbsd
|
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
|
CWE-287
Improper Authentication
|
CVE-2019-19519
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221928
|
7.8 |
HIGH
Local
|
sony
|
catalyst_browse catalyst_production_suite
|
A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-19364
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221929
|
6.1 |
MEDIUM
Network
|
csshero
|
csshero
|
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker …
|
CWE-79
Cross-site Scripting
|
CVE-2019-19133
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221930
|
6.8 |
MEDIUM
Physics
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not…
|
CWE-20
Improper Input Validation
|
CVE-2019-19579
|
2024-11-21 13:34 |
2019-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|