|
218881
|
8.8 |
HIGH
Network
|
libsdl debian opensuse canonical
|
sdl2_image debian_linux leap backports_sle ubuntu_linux
|
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocate…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-5052
|
2024-11-21 13:44 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218882
|
8.8 |
HIGH
Network
|
libsdl debian opensuse canonical
|
sdl2_image debian_linux leap backports_sle ubuntu_linux
|
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution…
|
CWE-787 CWE-755
Out-of-bounds Write Improper Handling of Exceptional Conditions
|
CVE-2019-5051
|
2024-11-21 13:44 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218883
|
7.8 |
HIGH
Local
|
haxx oracle netapp
|
curl http_server enterprise_manager_ops_center oss_support_tools mysql_server snapcenter oncommand_unified_manager oncommand_workflow_automation oncommand_insight
|
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-5443
|
2024-11-21 13:44 |
2019-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218884
|
5.3 |
MEDIUM
Network
|
netgear kcodes
|
r8000_firmware netusb.ko
|
An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potent…
|
CWE-200
Information Exposure
|
CVE-2019-5017
|
2024-11-21 13:44 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218885
|
9.1 |
CRITICAL
Network
|
netgear kcodes
|
r8000_firmware r7900_firmware netusb.ko
|
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadySHARE Printer functionality of at least two NETGEAR Nighthawk Routers and potent…
|
CWE-200
Information Exposure
|
CVE-2019-5016
|
2024-11-21 13:44 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218886
|
6.5 |
MEDIUM
Network
|
videolan
|
vlc_media_player
|
A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-5439
|
2024-11-21 13:44 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218887
|
6.1 |
MEDIUM
Network
|
huawei
|
hedex_lite
|
There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-5286
|
2024-11-21 13:44 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218888
|
5.3 |
MEDIUM
Local
|
huawei
|
hisuite
|
HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an attacker to load this D…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-5245
|
2024-11-21 13:44 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218889
|
7.5 |
HIGH
Network
|
pippo
|
pippo
|
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large amounts of heap memory is taken. Eventually, the JVM process will …
|
CWE-776
XML Entity Expansion
|
CVE-2019-5442
|
2024-11-21 13:44 |
2019-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218890
|
4.3 |
MEDIUM
Network
|
huawei
|
hg255s_firmware
|
There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-5243
|
2024-11-21 13:44 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|