|
218711
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2019-6261
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218712
|
9.8 |
CRITICAL
Network
|
numpy fedoraproject
|
numpy fedora
|
An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrate…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-6446
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218713
|
6.5 |
MEDIUM
Network
|
ntpsec
|
ntpsec
|
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-6445
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218714
|
9.1 |
CRITICAL
Network
|
ntpsec
|
ntpsec
|
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6444
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218715
|
9.1 |
CRITICAL
Network
|
ntpsec
|
ntpsec
|
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6443
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218716
|
6.5 |
MEDIUM
Network
|
ntpsec
|
ntpsec
|
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6442
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218717
|
9.8 |
CRITICAL
Network
|
zemana
|
antimalware
|
Zemana AntiMalware before 3.0.658 Beta mishandles update logic.
|
CWE-19
Data Processing Errors
|
CVE-2019-6440
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218718
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6439
|
2024-11-21 13:46 |
2019-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218719
|
9.8 |
CRITICAL
Network
|
skymoonlabs
|
cleanto
|
Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6296
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218720
|
9.8 |
CRITICAL
Network
|
skymoonlabs
|
cleanto
|
Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-6295
|
2024-11-21 13:46 |
2019-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|