|
224181
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-18675
|
2024-11-21 13:33 |
2019-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224182
|
6.8 |
MEDIUM
Physics
|
hp
|
thinpro
|
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.
|
CWE-78
OS Command
|
CVE-2019-18910
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224183
|
8.0 |
HIGH
Adjacent
|
hp
|
thinpro
|
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
|
CWE-78
OS Command
|
CVE-2019-18909
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224184
|
9.8 |
CRITICAL
Network
|
phpmyadmin opensuse fedoraproject
|
phpmyadmin leap fedora backports_sle
|
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
|
CWE-89
SQL Injection
|
CVE-2019-18622
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224185
|
8.8 |
HIGH
Network
|
digium debian
|
certified_asterisk asterisk debian_linux
|
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user withou…
|
CWE-862
Missing Authorization
|
CVE-2019-18610
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224186
|
7.5 |
HIGH
Network
|
digium debian
|
certified_asterisk asterisk debian_linux
|
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18976
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224187
|
6.5 |
MEDIUM
Network
|
digium debian
|
certified_asterisk asterisk debian_linux
|
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x before 17.0.1, and Certified Asterisk 13.21 before cert5. A SIP request can be sen…
|
CWE-862
Missing Authorization
|
CVE-2019-18790
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224188
|
8.8 |
HIGH
Network
|
pagekit
|
pagekit
|
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
|
CWE-352
Origin Validation Error
|
CVE-2019-19013
|
2024-11-21 13:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224189
|
9.8 |
CRITICAL
Network
|
zulip
|
zulip_server
|
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an …
|
NVD-CWE-noinfo
|
CVE-2019-18933
|
2024-11-21 13:33 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224190
|
9.8 |
CRITICAL
Network
|
sensiolabs fedoraproject
|
symfony fedora
|
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is rel…
|
CWE-94
Code Injection
|
CVE-2019-18889
|
2024-11-21 13:33 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|