|
224311
|
7.8 |
HIGH
Local
|
valvesoftware
|
steam_client
|
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This …
|
CWE-22
Path Traversal
|
CVE-2019-17180
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224312
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1
|
CWE-79
Cross-site Scripting
|
CVE-2019-17179
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224313
|
7.5 |
HIGH
Network
|
freerdp lodev opensuse
|
freerdp lodepng leap
|
HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argum…
|
CWE-252 CWE-401
Unchecked Return Value Missing Release of Memory after Effective Lifetime
|
CVE-2019-17178
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224314
|
7.5 |
HIGH
Network
|
freerdp opensuse
|
freerdp leap
|
libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc retur…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-17177
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224315
|
7.5 |
HIGH
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
|
CWE-22
Path Traversal
|
CVE-2019-17175
|
2024-11-21 13:31 |
2019-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224316
|
9.8 |
CRITICAL
Network
|
liferay
|
liferay_portal
|
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16891
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224317
|
9.8 |
CRITICAL
Network
|
linux debian canonical opensuse
|
linux_kernel debian_linux ubuntu_linux leap
|
In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17133
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224318
|
9.8 |
CRITICAL
Network
|
vbulletin
|
vbulletin
|
vBulletin through 5.5.4 mishandles custom avatars.
|
CWE-94 CWE-20
Code Injection Improper Input Validation
|
CVE-2019-17132
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224319
|
4.3 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
vBulletin before 5.5.4 allows clickjacking.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2019-17131
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224320
|
6.5 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2019-17130
|
2024-11-21 13:31 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|