|
221861
|
6.1 |
MEDIUM
Network
|
dicube
|
easescreen_crystal
|
Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components. This could be exploited when an attacker sends an crafted string for FTP authe…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20003
|
2024-11-21 13:37 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221862
|
8.8 |
HIGH
Network
|
intelbras
|
iwr_3000n_firmware
|
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2019-20004
|
2024-11-21 13:37 |
2020-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221863
|
8.8 |
HIGH
Network
|
symonics
|
libmysofa
|
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
|
CWE-665
Improper Initialization
|
CVE-2019-20063
|
2024-11-21 13:37 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221864
|
6.1 |
MEDIUM
Network
|
boltcms
|
bolt
|
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20058
|
2024-11-21 13:37 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221865
|
3.7 |
LOW
Network
|
proxyman
|
proxyman
|
com.proxyman.NSProxy.HelperTool in Privileged Helper Tool in Proxyman for macOS 1.11.0 and earlier allows an attacker to change the System Proxy and redirect all traffic to an attacker-controlled com…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-20057
|
2024-11-21 13:37 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221866
|
6.5 |
MEDIUM
Network
|
nothings
|
stb_image.h
|
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.
|
CWE-617
Reachable Assertion
|
CVE-2019-20056
|
2024-11-21 13:37 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221867
|
6.5 |
MEDIUM
Network
|
liquidpixels
|
liquifire_os
|
LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-20055
|
2024-11-21 13:37 |
2019-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221868
|
5.5 |
MEDIUM
Local
|
upx_project opensuse
|
upx leap backports
|
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-20053
|
2024-11-21 13:37 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221869
|
6.5 |
MEDIUM
Network
|
matio_project
|
matio
|
A memory leak was discovered in Mat_VarCalloc in mat.c in matio 1.5.17 because SafeMulDims does not consider the rank==0 case.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-20052
|
2024-11-21 13:37 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221870
|
5.5 |
MEDIUM
Local
|
upx_project fedoraproject
|
upx fedora
|
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.
|
CWE-682
Incorrect Calculation
|
CVE-2019-20051
|
2024-11-21 13:37 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|