|
222561
|
4.3 |
MEDIUM
Network
|
icegram
|
email_subscribers_\&_newsletters
|
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administra…
|
NVD-CWE-noinfo
|
CVE-2019-19980
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222562
|
8.8 |
HIGH
Network
|
wp_maintenance_project
|
wp_maintenance
|
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with re…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-19979
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222563
|
9.8 |
CRITICAL
Network
|
libesmtp_project
|
libesmtp
|
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19977
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222564
|
7.5 |
HIGH
Network
|
upc
|
connect_box_eurodocsis_firmware
|
The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Passwor…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-19967
|
2024-11-21 13:35 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222565
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-chann…
|
NVD-CWE-Other
|
CVE-2019-19963
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222566
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2019-19962
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222567
|
4.6 |
MEDIUM
Physics
|
linux debian opensuse netapp
|
linux_kernel debian_linux leap cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire_\&_hci_management_node active_iq_unified_manager solid…
|
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.
|
CWE-416
Use After Free
|
CVE-2019-19966
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222568
|
4.7 |
MEDIUM
Local
|
linux debian canonical netapp opensuse
|
linux_kernel debian_linux ubuntu_linux cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager e…
|
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-19965
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222569
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
|
NVD-CWE-Other
|
CVE-2019-19960
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222570
|
6.5 |
MEDIUM
Network
|
mz-automation
|
libiec61850
|
In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.
|
CWE-681 CWE-770
Incorrect Conversion between Numeric Types Allocation of Resources Without Limits or Throttling
|
CVE-2019-19958
|
2024-11-21 13:35 |
2019-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|