|
219741
|
5.5 |
MEDIUM
Local
|
elfutils_project
|
elfutils
|
In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-7146
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219742
|
5.5 |
MEDIUM
Local
|
elfutils_project debian canonical opensuse redhat
|
elfutils debian_linux ubuntu_linux leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_server_tus enter…
|
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn dat…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-7150
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219743
|
6.5 |
MEDIUM
Network
|
elfutils_project
|
elfutils
|
An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denia…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-7148
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219744
|
6.1 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROT…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6992
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219745
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a lon…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-6991
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219746
|
5.4 |
MEDIUM
Network
|
zoneminder
|
zoneminder
|
A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to th…
|
CWE-79
Cross-site Scripting
|
CVE-2019-6990
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219747
|
6.5 |
MEDIUM
Network
|
uclouvain
|
openjpeg
|
An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6988
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219748
|
7.5 |
HIGH
Network
|
duraspace
|
vitro
|
SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafte…
|
CWE-77 CWE-400
Command Injection Uncontrolled Resource Consumption
|
CVE-2019-6986
|
2024-11-21 13:47 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219749
|
8.8 |
HIGH
Network
|
foxitsoftware
|
3d
|
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Read in Indexing or a Heap Overflow and crash duri…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-6985
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219750
|
6.5 |
MEDIUM
Network
|
foxitsoftware
|
3d
|
An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter a Use-After-Free or Type Confusion and crash during handling of cer…
|
CWE-416 CWE-843
Use After Free Type Confusion
|
CVE-2019-6984
|
2024-11-21 13:47 |
2019-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|