|
218381
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7296
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218382
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
|
CWE-79
Cross-site Scripting
|
CVE-2019-7295
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218383
|
7.4 |
HIGH
Network
|
netkit debian
|
netkit debian_linux
|
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validatio…
|
NVD-CWE-noinfo
|
CVE-2019-7283
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218384
|
5.9 |
MEDIUM
Network
|
netkit debian fedoraproject
|
netkit debian_linux fedora
|
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of…
|
NVD-CWE-noinfo
|
CVE-2019-7282
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218385
|
6.1 |
MEDIUM
Network
|
cross_reference_project
|
cross_reference
|
An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configuration panel may allow a malicious user to use both label text and references t…
|
CWE-79
Cross-site Scripting
|
CVE-2019-7250
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218386
|
9.8 |
CRITICAL
Network
|
keybase
|
keybase
|
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper wit…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-7249
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218387
|
7.8 |
HIGH
Local
|
encodable
|
filechucker
|
An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user to upload any type of file by using % characters within the extension, e.g., fi…
|
NVD-CWE-noinfo
|
CVE-2019-7216
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218388
|
7.5 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=browse ..\ Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2019-7237
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218389
|
7.5 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2019-7236
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218390
|
7.5 |
HIGH
Network
|
idreamsoft
|
icms
|
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This…
|
CWE-22
Path Traversal
|
CVE-2019-7235
|
2024-11-21 13:47 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|