|
224431
|
5.5 |
MEDIUM
Local
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap…
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20091
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224432
|
7.8 |
HIGH
Local
|
axiosys
|
bento4
|
An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.
|
CWE-416
Use After Free
|
CVE-2019-20090
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224433
|
7.8 |
HIGH
Local
|
gopro
|
gpmf-parser
|
GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculation.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20089
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224434
|
7.8 |
HIGH
Local
|
gopro
|
gpmf-parser
|
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20088
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224435
|
8.8 |
HIGH
Network
|
gopro
|
gpmf-parser
|
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" feature.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20087
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224436
|
8.8 |
HIGH
Network
|
gopro
|
gpmf-parser
|
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20086
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224437
|
7.5 |
HIGH
Network
|
tvt
|
nvms-1000_firmware
|
TVT NVMS-1000 devices allow GET /.. Directory Traversal
|
CWE-22
Path Traversal
|
CVE-2019-20085
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224438
|
7.8 |
HIGH
Local
|
vim canonical
|
vim ubuntu_linux
|
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
|
CWE-416
Use After Free
|
CVE-2019-20079
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224439
|
6.1 |
MEDIUM
Network
|
netis-systems
|
dl4343_firmware
|
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
|
CWE-79
Cross-site Scripting
|
CVE-2019-20076
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224440
|
6.1 |
MEDIUM
Network
|
netis-systems
|
dl4343_firmware
|
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
|
CWE-79
Cross-site Scripting
|
CVE-2019-20075
|
2024-11-21 13:38 |
2019-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|