|
223401
|
5.5 |
MEDIUM
Local
|
linux canonical debian netapp
|
linux_kernel ubuntu_linux debian_linux steelstore_cloud_integrated_storage active_iq_unified_manager data_availability_services solidfire hci_management_node aff_a700s_firmwar…
|
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/…
|
CWE-416
Use After Free
|
CVE-2019-19813
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223402
|
6.5 |
MEDIUM
Network
|
spip debian canonical
|
spip debian_linux ubuntu_linux
|
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
|
NVD-CWE-noinfo
|
CVE-2019-19830
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223403
|
9.8 |
CRITICAL
Network
|
drupal
|
views_dynamic_field
|
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involv…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-19826
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223404
|
5.5 |
MEDIUM
Local
|
gonitro
|
nitro_free_pdf_reader
|
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19818
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223405
|
6.5 |
MEDIUM
Network
|
dlink
|
dir-615_t1_firmware
|
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
|
NVD-CWE-noinfo
|
CVE-2019-19743
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223406
|
7.5 |
HIGH
Network
|
roxyfileman
|
roxy_fileman
|
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by u…
|
CWE-22
Path Traversal
|
CVE-2019-19731
|
2024-11-21 13:35 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223407
|
6.5 |
MEDIUM
Network
|
cyrus debian fedoraproject canonical
|
imap debian_linux fedora ubuntu_linux
|
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19783
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223408
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. Th…
|
CWE-416
Use After Free
|
CVE-2019-19807
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223409
|
5.5 |
MEDIUM
Local
|
xfig_project fedoraproject debian
|
fig2dev fedora debian_linux
|
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19797
|
2024-11-21 13:35 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223410
|
7.8 |
HIGH
Local
|
yabasic
|
yabasic
|
Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-19796
|
2024-11-21 13:35 |
2019-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|