|
222381
|
9.8 |
CRITICAL
Network
|
strapi
|
strapi
|
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-18818
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222382
|
5.5 |
MEDIUM
Local
|
eximioussoft
|
logo_designer
|
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfile::BuildGradientColorsTable+0x0000000000000053.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18821
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222383
|
5.5 |
MEDIUM
Local
|
eximioussoft
|
logo_designer
|
Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18820
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222384
|
5.5 |
MEDIUM
Local
|
eximioussoft
|
logo_designer
|
Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-18819
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222385
|
6.1 |
MEDIUM
Network
|
popojicms
|
popojicms
|
po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18816
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222386
|
6.1 |
MEDIUM
Network
|
popojicms
|
popojicms
|
PopojiCMS 2.0.1 allows refer= Open Redirection.
|
CWE-601
Open Redirect
|
CVE-2019-18815
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222387
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c.
|
CWE-416
Use After Free
|
CVE-2019-18814
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222388
|
7.5 |
HIGH
Network
|
linux canonical
|
linux_kernel ubuntu_linux
|
A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platfo…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-18813
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222389
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-c0a333d842ef.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-18812
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222390
|
5.5 |
MEDIUM
Local
|
linux fedoraproject redhat
|
linux_kernel fedora enterprise_linux
|
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-18811
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|