|
224701
|
6.5 |
MEDIUM
Network
|
gnu opensuse canonical
|
binutils leap ubuntu_linux
|
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-17451
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224702
|
6.5 |
MEDIUM
Network
|
gnu opensuse canonical
|
binutils leap ubuntu_linux
|
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recurs…
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-17450
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224703
|
6.7 |
MEDIUM
Local
|
avira
|
software_updater
|
Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privi…
|
CWE-426
Untrusted Search Path
|
CVE-2019-17449
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224704
|
9.8 |
CRITICAL
Network
|
netsarang
|
xftp
|
NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads …
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-17320
|
2024-11-21 13:32 |
2019-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224705
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17434
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224706
|
4.8 |
MEDIUM
Network
|
laravel-admin
|
laravel-admin
|
z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation log" screen.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17433
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224707
|
6.5 |
MEDIUM
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] parameter.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2019-17432
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224708
|
8.8 |
HIGH
Network
|
fastadmin
|
fastadmin
|
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2019-17431
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224709
|
6.1 |
MEDIUM
Network
|
eyoucms
|
eyoucms
|
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2019-17430
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224710
|
9.8 |
CRITICAL
Network
|
adhouma_cms_project
|
adhouma_cms
|
Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
|
CWE-89
SQL Injection
|
CVE-2019-17429
|
2024-11-21 13:32 |
2019-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|