|
224581
|
7.5 |
HIGH
Network
|
proftpd
|
proftpd
|
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinit…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-18217
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224582
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17409
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224583
|
6.8 |
MEDIUM
Physics
|
asus
|
rog_zephyrus_m_gm501gs_firmware
|
The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in whi…
|
NVD-CWE-noinfo
|
CVE-2019-18216
|
2024-11-21 13:32 |
2019-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224584
|
7.7 |
HIGH
Network
|
video_converter_project
|
video_converter
|
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The worklo…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-18214
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224585
|
6.1 |
MEDIUM
Network
|
etherpad
|
etherpad
|
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
|
CWE-79
Cross-site Scripting
|
CVE-2019-18209
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224586
|
5.3 |
MEDIUM
Network
|
wago
|
pfc_firmware
|
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via craft…
|
NVD-CWE-noinfo
|
CVE-2019-18202
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224587
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag,…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-18198
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224588
|
7.5 |
HIGH
Network
|
xmlsoft debian canonical
|
libxslt debian_linux ubuntu_linux
|
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds ch…
|
CWE-416 CWE-908
Use After Free Use of Uninitialized Resource
|
CVE-2019-18197
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224589
|
9.8 |
CRITICAL
Network
|
sagemath
|
sagemathcell
|
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary c…
|
CWE-94 CWE-78
Code Injection OS Command
|
CVE-2019-17526
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224590
|
9.8 |
CRITICAL
Network
|
tomedo
|
server
|
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authent…
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-17393
|
2024-11-21 13:32 |
2019-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|