|
219561
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger thi…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5048
|
2024-11-21 13:44 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219562
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
An exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a type confusion, resulting in a Use After Free. An attacker c…
|
CWE-416 CWE-843
Use After Free Type Confusion
|
CVE-2019-5047
|
2024-11-21 13:44 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219563
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbit…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5046
|
2024-11-21 13:44 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219564
|
7.8 |
HIGH
Local
|
gonitro
|
nitropdf
|
A specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbit…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5045
|
2024-11-21 13:44 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219565
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828. A specially crafted PDF document can trigger an out-of-memory…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-5031
|
2024-11-21 13:44 |
2019-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219566
|
6.7 |
MEDIUM
Local
|
e2fsprogs_project debian fedoraproject canonical netapp
|
e2fsprogs debian_linux fedora ubuntu_linux solidfire hci_management_node
|
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in c…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5094
|
2024-11-21 13:44 |
2019-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219567
|
9.8 |
CRITICAL
Network
|
aspose
|
aspose.pdf_for_c\+\+
|
An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object pointers. A specially crafted PDF can cause a read and write from uninitialized me…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-5067
|
2024-11-21 13:44 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219568
|
9.8 |
CRITICAL
Network
|
aspose
|
aspose.pdf_for_c\+\+
|
An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resulting in …
|
CWE-416
Use After Free
|
CVE-2019-5066
|
2024-11-21 13:44 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219569
|
8.8 |
HIGH
Network
|
aspose
|
aspose.pdf_for_c\+\+
|
An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19.2 for C++. A specially crafted PDF can cause a dangling heap pointer, resultin…
|
CWE-416
Use After Free
|
CVE-2019-5042
|
2024-11-21 13:44 |
2019-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219570
|
7.2 |
HIGH
Network
|
arubanetworks
|
arubaos
|
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system. A maliciou…
|
CWE-78
OS Command
|
CVE-2019-5315
|
2024-11-21 13:44 |
2019-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|