|
221741
|
8.8 |
HIGH
Network
|
libsdl opensuse
|
sdl2_image leap backports_sle
|
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5058
|
2024-11-21 13:44 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221742
|
8.8 |
HIGH
Network
|
libsdl opensuse
|
sdl2_image leap backports_sle
|
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-5057
|
2024-11-21 13:44 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221743
|
5.5 |
MEDIUM
Local
|
virustotal
|
yara
|
An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, res…
|
CWE-754 CWE-617
Improper Check for Unusual or Exceptional Conditions Reachable Assertion
|
CVE-2019-5020
|
2024-11-21 13:44 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221744
|
5.5 |
MEDIUM
Local
|
videolan opensuse
|
vlc_media_player leap backports
|
Double Free in VLC versions <= 3.0.6 leads to a crash.
|
CWE-415
Double Free
|
CVE-2019-5460
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221745
|
7.1 |
HIGH
Local
|
videolan opensuse
|
vlc_media_player leap backports backports_sle
|
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2019-5459
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221746
|
5.4 |
MEDIUM
Network
|
http-file-server_project
|
http-file-server
|
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5458
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221747
|
5.4 |
MEDIUM
Network
|
min-http-server_project
|
min-http-server
|
Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
|
CWE-79
Cross-site Scripting
|
CVE-2019-5457
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221748
|
8.1 |
HIGH
Network
|
ui
|
unifi_controller
|
SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use l…
|
CWE-255
Credentials Management
|
CVE-2019-5456
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221749
|
6.8 |
MEDIUM
Physics
|
nextcloud
|
nextcloud
|
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
|
CWE-287
Improper Authentication
|
CVE-2019-5455
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221750
|
9.8 |
CRITICAL
Network
|
nextcloud
|
nextcloud
|
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.
|
CWE-89
SQL Injection
|
CVE-2019-5454
|
2024-11-21 13:44 |
2019-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|