|
222361
|
7.5 |
HIGH
Network
|
istio
|
istio
|
Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related issue to CVE-2019-18836.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18817
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222362
|
9.8 |
CRITICAL
Network
|
helm
|
helm
|
In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opportunity for a maliciously designed chart to include sensitive content such as /et…
|
CWE-59
Link Following
|
CVE-2019-18658
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222363
|
6.1 |
MEDIUM
Network
|
wso2
|
identity_server
|
WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18882
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222364
|
6.1 |
MEDIUM
Network
|
wso2
|
identity_server
|
WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18881
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222365
|
7.5 |
HIGH
Network
|
psutil_project
|
psutil
|
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
|
CWE-415
Double Free
|
CVE-2019-18874
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222366
|
7.8 |
HIGH
Local
|
gnu
|
mailutils
|
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
|
NVD-CWE-noinfo
|
CVE-2019-18862
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222367
|
7.5 |
HIGH
Network
|
svg-sanitizer_project
|
svg-sanitizer
|
darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18857
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222368
|
7.5 |
HIGH
Network
|
drupal
|
svg_sanitizer
|
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-18856
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222369
|
7.5 |
HIGH
Network
|
10up
|
safe_svg
|
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to potentially unwanted elements or attributes.
|
NVD-CWE-noinfo
|
CVE-2019-18855
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222370
|
7.5 |
HIGH
Network
|
10up
|
safe_svg
|
A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to unlimited recursion for a '<use ... xlink:href="#identifier">' substring.
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-18854
|
2024-11-21 13:33 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|