|
224601
|
6.5 |
MEDIUM
Network
|
emlog
|
emlog
|
emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2019-17073
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224602
|
6.1 |
MEDIUM
Network
|
eclipse oracle
|
mojarra mojarra_javaserver_faces retail_service_backbone retail_integration_bus retail_merchandising_system application_testing_suite secure_global_desktop retail_financial_integ…
|
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client windo…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17091
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224603
|
7.5 |
HIGH
Network
|
putty opensuse netapp
|
putty leap oncommand_unified_manager_core_package
|
PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via an SSH1_MSG_DISCONNECT message.
|
CWE-416
Use After Free
|
CVE-2019-17069
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224604
|
7.5 |
HIGH
Network
|
putty opensuse
|
putty leap
|
PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.
|
CWE-74
Injection
|
CVE-2019-17068
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224605
|
9.8 |
CRITICAL
Network
|
putty
|
putty
|
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-17067
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224606
|
9.8 |
CRITICAL
Network
|
fasterxml debian fedoraproject redhat oracle netapp
|
jackson-databind debian_linux fedora jboss_enterprise_application_platform banking_platform jd_edwards_enterpriseone_tools primavera_gateway weblogic_server webcenter_portal
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16943
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224607
|
9.8 |
CRITICAL
Network
|
fasterxml debian fedoraproject redhat netapp oracle
|
jackson-databind debian_linux fedora jboss_enterprise_application_platform steelstore_cloud_integrated_storage oncommand_workflow_automation service_level_manager oncommand_api_s…
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16942
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224608
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17064
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224609
|
5.5 |
MEDIUM
Local
|
snowtide
|
pdfxstream
|
In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.
|
NVD-CWE-noinfo
|
CVE-2019-17063
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224610
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka C…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17056
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|