CVE-2019-11000 to CVE-2019-11999
158 CVEs with public proof-of-concept exploits.
- CVE-2019-110012 PoCsKEVOn Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail"…
- CVE-2019-110021 PoCIn Materialize through 1.0.0, XSS is possible via the Tooltip feature.
- CVE-2019-110031 PoCIn Materialize through 1.0.0, XSS is possible via the Autocomplete feature.
- CVE-2019-110041 PoCIn Materialize through 1.0.0, XSS is possible via the Toast feature.
- CVE-2019-110133 PoCsNimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to…
- CVE-2019-110151 PoCA vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscreen based…
- CVE-2019-110172 PoCsOn D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration: /spap.htm,…
- CVE-2019-110181 PoCapplication\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials…
- CVE-2019-110232 PoCsThe agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by…
- CVE-2019-110242 PoCsThe load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
- CVE-2019-110262 PoCsFontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
- CVE-2019-110381 PoCUninitialized read in gdImageCreateFromXbm
- CVE-2019-110391 PoCOut-of-bounds read in iconv.c
- CVE-2019-1104334 PoCsKEVUnderflow in PHP-FPM can lead to RCE
- CVE-2019-110441 PoClink() silently truncates after a null byte on Windows
- CVE-2019-110451 PoCDirectoryIterator class silently truncates after a null byte
- CVE-2019-110482 PoCsTemporary files are not cleaned after OOM when parsing HTTP request data
- CVE-2019-110601 PoCHG100 contains an Uncontrolled Resource Consumption vulnerability
- CVE-2019-110611 PoCHG100 has a broken access control vulnerability in its Web API Server
- CVE-2019-110631 PoCSmartHome application has a broken access control vulnerability in its Web API Server
- CVE-2019-110641 PoCA vulnerability of remote credential disclosure was discovered in Advan VD-1
- CVE-2019-110731 PoCA Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to…
- CVE-2019-110741 PoCA Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files…
- CVE-2019-110761 PoCCribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
- CVE-2019-110801 PoCSitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 293863. An…
- CVE-2019-111851 PoCThe WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an…
- CVE-2019-111902 PoCsThe Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called…
- CVE-2019-111912 PoCsThe Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid…
- CVE-2019-111932 PoCsThe FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESELLER; an attacker…
- CVE-2019-111991 PoCDolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript…
- CVE-2019-112001 PoCDolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application…
- CVE-2019-112011 PoCDolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was…
- CVE-2019-112162 PoCsBMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform…
- CVE-2019-112232 PoCsAn Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute…
- CVE-2019-112241 PoCHARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.
- CVE-2019-112262 PoCsCMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
- CVE-2019-112292 PoCsmodels/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
- CVE-2019-112315 PoCsAn issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files…
- CVE-2019-112482 PoCsKubernetes kubelet exposes /debug/pprof info on healthz port
- CVE-2019-112532 PoCsKubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
- CVE-2019-112691 PoCOpen Redirector in spring-security-oauth2
- CVE-2019-112872 PoCsRabbitMQ Web Management Plugin DoS via heap overflow
- CVE-2019-113191 PoCAn issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which…
- CVE-2019-113201 PoCIn Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrated by the…
- CVE-2019-113211 PoCAn issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port…
- CVE-2019-113221 PoCAn issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads…
- CVE-2019-113271 PoCAn issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a…
- CVE-2019-113281 PoCAn issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could…
- CVE-2019-113321 PoCMKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php,…
- CVE-2019-113341 PoCAn authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile devices allows attackers…
- CVE-2019-113361 PoCSony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point)…
- CVE-2019-113531 PoCThe EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute…
- CVE-2019-113545 PoCsThe client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler.…
- CVE-2019-1135888 PoCsjQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of…
- CVE-2019-113591 PoCCross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or…
- CVE-2019-113601 PoCA buffer overflow in iptables-restore in netfilter iptables 1.8.2 allows an attacker to (at least) crash the program or potentially gain…
- CVE-2019-113651 PoCAn issue was discovered in atftpd in atftp 0.7.1. A remote attacker may send a crafted packet triggering a stack-based buffer overflow due…
- CVE-2019-113661 PoCAn issue was discovered in atftpd in atftp 0.7.1. It does not lock the thread_list_mutex mutex before assigning the current thread data…
- CVE-2019-113672 PoCsAn issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account…
- CVE-2019-113682 PoCsStored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter.
- CVE-2019-113692 PoCsAn issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may…
- CVE-2019-113703 PoCsStored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.
- CVE-2019-113721 PoCAn out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12…
- CVE-2019-113731 PoCAn out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
- CVE-2019-113743 PoCs74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
- CVE-2019-113752 PoCsMsvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.
- CVE-2019-113771 PoCwcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is a valid extension…
- CVE-2019-113831 PoCAn issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/password of a valid…
- CVE-2019-113841 PoCThe Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), which allows a…
- CVE-2019-113931 PoCAn issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an…
- CVE-2019-1139514 PoCsA buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrated by SMTP RCPT…
- CVE-2019-113982 PoCsMultiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or…
- CVE-2019-114011 PoCA issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the…
- CVE-2019-114042 PoCsarrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS.…
- CVE-2019-114051 PoCOpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and…
- CVE-2019-114061 PoCSubrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
- CVE-2019-114082 PoCsXSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated attackers to inject…
- CVE-2019-114095 PoCsapp/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack…
- CVE-2019-114152 PoCsAn issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of…
- CVE-2019-114162 PoCsA CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by…
- CVE-2019-114191 PoCvcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of…
- CVE-2019-114281 PoCI, Librarian 4.10 has XSS via the export.php export_files parameter.
- CVE-2019-114292 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro) is vulnerable to…
- CVE-2019-114442 PoCsAn issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands.…
- CVE-2019-114452 PoCsOpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move that file to the home…
- CVE-2019-114462 PoCsAn issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user privilege. The…
- CVE-2019-114479 PoCsAn issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile…
- CVE-2019-114483 PoCsAn issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of…
- CVE-2019-114551 PoCA buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the…
- CVE-2019-114561 PoCGila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
- CVE-2019-114693 PoCsZoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an…
- CVE-2019-114761 PoCInteger overflow in whoopsie results in out-of-bounds heap write
- CVE-2019-114771 PoCInteger overflow in TCP_SKB_CB(skb)->tcp_gso_segs
- CVE-2019-114901 PoCAn issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or…
- CVE-2019-115021 PoCsnap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user.…
- CVE-2019-115031 PoCsnap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working…
- CVE-2019-115042 PoCsZotonic before version 0.47 has mod_admin XSS.
- CVE-2019-115072 PoCsIn Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application…
- CVE-2019-115081 PoCIn Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an…
- CVE-2019-1151019 PoCsKEVIn Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote…
- CVE-2019-115151 PoCcore/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary files.
- CVE-2019-115171 PoCWampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was…
- CVE-2019-115221 PoCOX App Suite 7.10.0 to 7.10.2 allows XSS.
- CVE-2019-115231 PoCAnviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers…
- CVE-2019-115261 PoCAn issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path…
- CVE-2019-115271 PoCAn issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url…
- CVE-2019-115281 PoCAn issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.
- CVE-2019-115371 PoCIn osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if…
- CVE-2019-115381 PoCIn Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1,…
- CVE-2019-115396 PoCsKEVIn Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1…
- CVE-2019-115401 PoCIn Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before…
- CVE-2019-115421 PoCIn Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1…
- CVE-2019-115491 PoCAn issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x…
- CVE-2019-115521 PoCCode42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval…
- CVE-2019-115571 PoCThe WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with…
- CVE-2019-115641 PoCA cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HTML via a…
- CVE-2019-115651 PoCServer Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
- CVE-2019-115691 PoCVeeam ONE Reporter 9.5.0.3201 allows CSRF.
- CVE-2019-115805 PoCsKEVAtlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send…
- CVE-2019-115817 PoCsKEVThere was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail…
- CVE-2019-115902 PoCsThe 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local…
- CVE-2019-115912 PoCsThe WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant…
- CVE-2019-115971 PoCIn ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an…
- CVE-2019-115981 PoCIn ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an…
- CVE-2019-115993 PoCsThe coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags…
- CVE-2019-116005 PoCsA SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands…
- CVE-2019-116042 PoCsAn issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is…
- CVE-2019-116371 PoCAn issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in…
- CVE-2019-116381 PoCAn issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at…
- CVE-2019-116391 PoCAn issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in…
- CVE-2019-116401 PoCAn issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c…
- CVE-2019-116602 PoCsPrivileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This…
- CVE-2019-116821 PoCA buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP…
- CVE-2019-116873 PoCsAn issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current…
- CVE-2019-116881 PoCAn issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl accept any…
- CVE-2019-116891 PoCAn issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to…
- CVE-2019-117032 PoCsA flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email…
- CVE-2019-117041 PoCA flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain…
- CVE-2019-117051 PoCA flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email…
- CVE-2019-117061 PoCA flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain…
- CVE-2019-117078 PoCsKEVA type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an…
- CVE-2019-117084 PoCsKEVInsufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the…
- CVE-2019-117301 PoCA vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same…
- CVE-2019-117381 PoCIf a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of…
- CVE-2019-117701 PoCIn Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of…
- CVE-2019-118061 PoCOX App Suite 7.10.1 and earlier has Insecure Permissions.
- CVE-2019-118231 PoCCRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a…
- CVE-2019-118411 PoCA message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25.…
- CVE-2019-118451 PoCAn HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn…
- CVE-2019-118461 PoC/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
- CVE-2019-118693 PoCsThe Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that the request comes…
- CVE-2019-118752 PoCsIn AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate…
- CVE-2019-118781 PoCAn issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same local network as…
- CVE-2019-118811 PoCA vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to display arbitrary…
- CVE-2019-118862 PoCsThe WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress allows…
- CVE-2019-119311 PoCA stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was…
- CVE-2019-1193227 PoCsA double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in…
- CVE-2019-119332 PoCsA heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow…