|
223361
|
8.8 |
HIGH
Network
|
sfu
|
open_journal_system
|
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an auth…
|
CWE-94 CWE-502
Code Injection Deserialization of Untrusted Data
|
CVE-2019-19909
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223362
|
9.8 |
CRITICAL
Network
|
kopano
|
groupware_core
|
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19907
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223363
|
7.5 |
HIGH
Network
|
cyrusimap debian canonical fedoraproject redhat apple apache
|
cyrus-sasl debian_linux ubuntu_linux fedora enterprise_linux jboss_enterprise_web_server mac_os_x enterprise_linux_server_for_power_little_endian_update_services_for_sap_solution…
|
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by a…
|
CWE-787 CWE-193
Out-of-bounds Write Off-by-one Error
|
CVE-2019-19906
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223364
|
9.8 |
CRITICAL
Network
|
nethack
|
nethack
|
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared sy…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-19905
|
2024-11-21 13:35 |
2019-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223365
|
4.8 |
MEDIUM
Network
|
backdropcms
|
backdrop_cms
|
An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially cra…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19903
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223366
|
7.2 |
HIGH
Network
|
backdropcms
|
backdrop_cms
|
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does n…
|
CWE-20
Improper Input Validation
|
CVE-2019-19902
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223367
|
4.8 |
MEDIUM
Network
|
backdropcms
|
backdrop_cms
|
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19900
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223368
|
4.8 |
MEDIUM
Network
|
backdropcms
|
backdrop_cms
|
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An a…
|
CWE-79
Cross-site Scripting
|
CVE-2019-19901
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223369
|
9.8 |
CRITICAL
Network
|
pebbletemplates
|
pebble_templates
|
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Clas…
|
CWE-862
Missing Authorization
|
CVE-2019-19899
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223370
|
5.5 |
MEDIUM
Local
|
opera
|
opera
|
Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandb…
|
NVD-CWE-Other
|
CVE-2019-19788
|
2024-11-21 13:35 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|