|
221911
|
7.8 |
HIGH
Local
|
shanda
|
maplestory_online
|
In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signe…
|
CWE-787 CWE-129
Out-of-bounds Write Improper Validation of Array Index
|
CVE-2019-9729
|
2024-11-21 13:52 |
2019-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221912
|
6.1 |
MEDIUM
Network
|
korenix
|
jetport_web_manager jetport_5601_firmware jetport_5601f_firmware
|
The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field under Serial Setting.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9725
|
2024-11-21 13:52 |
2019-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221913
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9714
|
2024-11-21 13:52 |
2019-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221914
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
|
CWE-862
Missing Authorization
|
CVE-2019-9713
|
2024-11-21 13:52 |
2019-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221915
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9712
|
2024-11-21 13:52 |
2019-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221916
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-9711
|
2024-11-21 13:52 |
2019-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221917
|
6.5 |
MEDIUM
Network
|
ffmpeg canonical
|
ffmpeg ubuntu_linux
|
A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, because handle_open_brace in libavcodec/htmlsubtitles.c …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9721
|
2024-11-21 13:52 |
2019-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221918
|
6.5 |
MEDIUM
Network
|
ffmpeg debian canonical
|
ffmpeg debian_linux ubuntu_linux
|
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitle…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-9718
|
2024-11-21 13:52 |
2019-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221919
|
5.4 |
MEDIUM
Network
|
jupyter
|
notebook
|
An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Acces…
|
CWE-79
Cross-site Scripting
|
CVE-2019-9644
|
2024-11-21 13:52 |
2019-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221920
|
8.1 |
HIGH
Network
|
webargs_project
|
webargs
|
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the parsed JSON body. This cache is not thread-safe, meani…
|
CWE-362
Race Condition
|
CVE-2019-9710
|
2024-11-21 13:52 |
2019-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|