|
219001
|
9.8 |
CRITICAL
Network
|
irssi canonical
|
irssi ubuntu_linux
|
Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
|
CWE-416
Use After Free
|
CVE-2019-5882
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219002
|
9.8 |
CRITICAL
Network
|
traccar
|
server
|
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
|
CWE-611
XXE
|
CVE-2019-5748
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219003
|
7.5 |
HIGH
Network
|
busybox canonical
|
busybox ubuntu_linux
|
An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) might allow a remote attacker to leak sensitive inform…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5747
|
2024-11-21 13:45 |
2019-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219004
|
7.5 |
HIGH
Network
|
qibosoft
|
qibosoft
|
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the same web site to read a .sql file.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-5725
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219005
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by changing the memory-management approach so that a use-after-free is avoided.
|
CWE-416
Use After Free
|
CVE-2019-5721
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219006
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data blo…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2019-5719
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219007
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-5718
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219008
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.
|
CWE-20
Improper Input Validation
|
CVE-2019-5717
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219009
|
5.5 |
MEDIUM
Local
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.
|
CWE-20
Improper Input Validation
|
CVE-2019-5716
|
2024-11-21 13:45 |
2019-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219010
|
9.8 |
CRITICAL
Network
|
frontaccounting
|
frontaccounting
|
includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application via…
|
CWE-89
SQL Injection
|
CVE-2019-5720
|
2024-11-21 13:45 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|