CVE-2019-5000 to CVE-2019-5999
221 CVEs with public proof-of-concept exploits.
- CVE-2019-50092 PoCsVtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG…
- CVE-2019-50102 PoCsAn exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially…
- CVE-2019-50151 PoCA local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper helper tool. A user…
- CVE-2019-50181 PoCAn exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command…
- CVE-2019-50191 PoCA heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter…
- CVE-2019-50201 PoCAn exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file…
- CVE-2019-50211 PoCVersions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears…
- CVE-2019-50231 PoCAn exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to…
- CVE-2019-50295 PoCsAn exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary…
- CVE-2019-50301 PoCA buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0…
- CVE-2019-50311 PoCAn exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.4.1.16828.…
- CVE-2019-50341 PoCAn exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version…
- CVE-2019-50351 PoCAn exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version…
- CVE-2019-50361 PoCAn exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version…
- CVE-2019-50371 PoCAn exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version…
- CVE-2019-50381 PoCAn exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a…
- CVE-2019-50391 PoCAn exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A…
- CVE-2019-50401 PoCAn exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam…
- CVE-2019-50421 PoCAn exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19.2 for C++. A…
- CVE-2019-50431 PoCAn exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP…
- CVE-2019-50451 PoCA specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF…
- CVE-2019-50461 PoCA specifically crafted jpeg2000 file embedded in a PDF file can lead to a heap corruption when opening a PDF document in NitroPDF…
- CVE-2019-50471 PoCAn exploitable Use After Free vulnerability exists in the CharProcs parsing functionality of NitroPDF. A specially crafted PDF can cause a…
- CVE-2019-50481 PoCA specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this…
- CVE-2019-50501 PoCA specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this…
- CVE-2019-50511 PoCAn exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error…
- CVE-2019-50521 PoCAn exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an…
- CVE-2019-50531 PoCAn exploitable use-after-free vulnerability exists in the Length parsing function of NitroPDF. A specially crafted PDF can cause a type…
- CVE-2019-50541 PoCAn exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000v5 with Firmware…
- CVE-2019-50551 PoCAn exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR2000v5 with…
- CVE-2019-50601 PoCAn exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image…
- CVE-2019-50631 PoCAn exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0. A specially…
- CVE-2019-50641 PoCAn exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0.…
- CVE-2019-50651 PoCAn exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. A specially…
- CVE-2019-50681 PoCAn exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can…
- CVE-2019-50691 PoCA code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization…
- CVE-2019-50701 PoCAn exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially…
- CVE-2019-50711 PoCAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart…
- CVE-2019-50721 PoCAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart…
- CVE-2019-50731 PoCAn exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware…
- CVE-2019-50751 PoCAn exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions…
- CVE-2019-50761 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG header-parser of the Accusoft ImageGear 19.3.0 library. A…
- CVE-2019-50791 PoCAn exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware…
- CVE-2019-50811 PoCAn exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware…
- CVE-2019-50821 PoCAn exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version…
- CVE-2019-50831 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft ImageGear 19.3.0…
- CVE-2019-50841 PoCAn exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20. A specially crafted TIF…
- CVE-2019-50862 PoCsAn exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools,…
- CVE-2019-50871 PoCAn exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools…
- CVE-2019-50881 PoCAn exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file…
- CVE-2019-50891 PoCAn exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file…
- CVE-2019-50941 PoCAn exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition…
- CVE-2019-50951 PoCAn issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticated users can…
- CVE-2019-50962 PoCsAn exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server…
- CVE-2019-50971 PoCA denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in…
- CVE-2019-50981 PoCAn exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel…
- CVE-2019-50991 PoCAn exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially crafted CMP image file…
- CVE-2019-51001 PoCAn exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A specially crafted BMP…
- CVE-2019-51011 PoCAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting…
- CVE-2019-51021 PoCAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting…
- CVE-2019-51051 PoCAn exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS…
- CVE-2019-51061 PoCA hard-coded encryption key vulnerability exists in the authentication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with…
- CVE-2019-51081 PoCAn exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this…
- CVE-2019-51091 PoCExploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause…
- CVE-2019-51101 PoCExploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web requests can cause…
- CVE-2019-51111 PoCExploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and…
- CVE-2019-51121 PoCExploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.php URL and…
- CVE-2019-51141 PoCAn exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause…
- CVE-2019-51161 PoCAn exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a…
- CVE-2019-51171 PoCExploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause…
- CVE-2019-51201 PoCAn exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause…
- CVE-2019-51211 PoCSQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections.…
- CVE-2019-51221 PoCSQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections.…
- CVE-2019-51231 PoCSpecially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in…
- CVE-2019-51251 PoCAn exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially crafted J2K image…
- CVE-2019-51261 PoCAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted…
- CVE-2019-51274 PoCsA command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server.…
- CVE-2019-51283 PoCsA command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server.…
- CVE-2019-51294 PoCsA command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server.…
- CVE-2019-51301 PoCAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.7.0.29435. A…
- CVE-2019-51311 PoCAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, version 9.7.0.29435. A…
- CVE-2019-51321 PoCAn exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear 19.3.0 library. A…
- CVE-2019-51341 PoCAn exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of…
- CVE-2019-51351 PoCAn exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web…
- CVE-2019-51361 PoCAn exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A…
- CVE-2019-51371 PoCThe usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network…
- CVE-2019-51381 PoCAn exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version…
- CVE-2019-51391 PoCAn exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13.…
- CVE-2019-51411 PoCAn exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A…
- CVE-2019-51421 PoCAn exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A…
- CVE-2019-51431 PoCAn exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version…
- CVE-2019-51451 PoCAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit PDF Reader, version 9.7.0.29435. A specially crafted…
- CVE-2019-51481 PoCAn exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A…
- CVE-2019-51491 PoCThe WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web…
- CVE-2019-51501 PoCAn exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted…
- CVE-2019-51511 PoCAn exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL…
- CVE-2019-51521 PoCAn exploitable information disclosure vulnerability exists in the network packet handling functionality of Shadowsocks-libev 3.3.2. When…
- CVE-2019-51531 PoCAn exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A…
- CVE-2019-51551 PoCAn exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating…
- CVE-2019-51561 PoCAn exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14),…
- CVE-2019-51571 PoCAn exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions…
- CVE-2019-51591 PoCAn exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software…
- CVE-2019-51601 PoCAn exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions…
- CVE-2019-51611 PoCAn exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14),…
- CVE-2019-51621 PoCAn exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware…
- CVE-2019-51631 PoCAn exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream…
- CVE-2019-51641 PoCAn exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets…
- CVE-2019-51651 PoCAn exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A…
- CVE-2019-51661 PoCAn exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version…
- CVE-2019-51671 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version…
- CVE-2019-51681 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version…
- CVE-2019-51691 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version…
- CVE-2019-51701 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version…
- CVE-2019-51711 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version…
- CVE-2019-51721 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version…
- CVE-2019-51731 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version…
- CVE-2019-51741 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version…
- CVE-2019-51751 PoCAn exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version…
- CVE-2019-51761 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51771 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51781 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51791 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51801 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51811 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51821 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200…
- CVE-2019-51841 PoCAn exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A specially crafted XML…
- CVE-2019-51851 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200.…
- CVE-2019-51861 PoCAn exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200.…
- CVE-2019-51871 PoCAn exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft…
- CVE-2019-51881 PoCA code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4…
- CVE-2019-53923 PoCsA disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
- CVE-2019-54134 PoCsAn attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
- CVE-2019-54142 PoCsIf an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of…
- CVE-2019-54151 PoCA bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the…
- CVE-2019-54161 PoCA path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitrary files on the…
- CVE-2019-54171 PoCA path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote…
- CVE-2019-541815 PoCsKEVThere is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted…
- CVE-2019-54191 PoCThere is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted…
- CVE-2019-542016 PoCsA remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically…
- CVE-2019-54231 PoCPath traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on the file system by a…
- CVE-2019-54271 PoCc3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against…
- CVE-2019-54321 PoCA specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 -…
- CVE-2019-54331 PoCA user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin…
- CVE-2019-54342 PoCsAn attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what"…
- CVE-2019-54371 PoCInformation exposure through the directory listing in npm's harp module allows to access files that are supposed to be ignored according…
- CVE-2019-54381 PoCPath traversal using symlink in npm harp module versions <= 0.29.0.
- CVE-2019-54421 PoCXML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entities are created recursively and large…
- CVE-2019-54442 PoCsPath traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.
- CVE-2019-54471 PoCA path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
- CVE-2019-54501 PoCImproper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name…
- CVE-2019-54521 PoCBypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android…
- CVE-2019-54531 PoCBypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock…
- CVE-2019-54551 PoCBypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
- CVE-2019-54571 PoCCross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to…
- CVE-2019-54581 PoCCross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to…
- CVE-2019-54591 PoCAn Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
- CVE-2019-54601 PoCDouble Free in VLC versions <= 3.0.6 leads to a crash.
- CVE-2019-54611 PoCAn input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make…
- CVE-2019-54631 PoCAn authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status.…
- CVE-2019-54641 PoCA flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF…
- CVE-2019-54671 PoCAn input validation and output encoding issue was discovered in the GitLab CE/EE wiki pages feature which could result in a persistent…
- CVE-2019-54681 PoCAn privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used…
- CVE-2019-54691 PoCAn IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace…
- CVE-2019-54711 PoCAn input validation and output encoding issue was discovered in the GitLab email notification feature which could result in a persistent…
- CVE-2019-54732 PoCsAn authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitLab 12.1.2 and…
- CVE-2019-54755 PoCsThe Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied…
- CVE-2019-54792 PoCsAn unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).
- CVE-2019-54801 PoCA path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
- CVE-2019-54832 PoCsSeneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.
- CVE-2019-54843 PoCsBower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, which allows…
- CVE-2019-54853 PoCsNPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the…
- CVE-2019-54861 PoCA authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that…
- CVE-2019-54871 PoCAn improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with…
- CVE-2019-54891 PoCThe mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access…
- CVE-2019-55121 PoCVMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successful…
- CVE-2019-55261 PoCVMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application.…
- CVE-2019-55442 PoCsKEVOpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be…
- CVE-2019-55912 PoCsKEVA Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive…
- CVE-2019-55963 PoCsIn FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the…
- CVE-2019-56021 PoCIn FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1,…
- CVE-2019-56031 PoCIn FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before…
- CVE-2019-56111 PoCIn FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before…
- CVE-2019-56182 PoCsA-PDF WAV to MP3 Stack-based Buffer Overflow
- CVE-2019-56192 PoCsAASync.com AASync Stack-based Buffer Overflow
- CVE-2019-56202 PoCsABB MicroSCADA Pro SYS600 Missing Authentication for Critical Function
- CVE-2019-56212 PoCsABBS Software Audio Media Player Stack-based Buffer Overflow
- CVE-2019-56221 PoCAccellion File Transfer Appliance Use of Hard-coded Credentials
- CVE-2019-56231 PoCAccellion File Transfer Appliance Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2019-56242 PoCsRapid7 Metasploit Framework Zip Import Directory Traversal
- CVE-2019-56291 PoCRapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path.…
- CVE-2019-56301 PoCRapid7 Nexpose/InsightVM Security Console CSRF
- CVE-2019-56451 PoCRapid7 Metasploit HTTP Handler Denial of Service
- CVE-2019-56881 PoCNVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys,…
- CVE-2019-56941 PoCNVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads…
- CVE-2019-56951 PoCNVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service…
- CVE-2019-57001 PoCNVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate…
- CVE-2019-57181 PoCIn Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in…
- CVE-2019-57201 PoCincludes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow…
- CVE-2019-57224 PoCsAn issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has…
- CVE-2019-57233 PoCsAn issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather than as a hash…
- CVE-2019-573661 PoCsrunc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and…
- CVE-2019-57371 PoCIn Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of…
- CVE-2019-57471 PoCAn issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or…
- CVE-2019-57632 PoCsFailure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap…
- CVE-2019-57823 PoCsIncorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside…
- CVE-2019-57842 PoCsIncorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentially exploit heap…
- CVE-2019-57863 PoCsKEVObject lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds…
- CVE-2019-57881 PoCAn integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote…
- CVE-2019-57891 PoCAn integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker…
- CVE-2019-57961 PoCData race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2019-57971 PoCDouble free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2019-58221 PoCInappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a…
- CVE-2019-58254 PoCsKEVOut of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2019-58271 PoCInteger overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap…
- CVE-2019-58701 PoCUse after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a…
- CVE-2019-58771 PoCOut of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap…
- CVE-2019-58932 PoCsNelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
- CVE-2019-59941 PoCBuffer overflow in PTP (Picture Transfer Protocol) of EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X…
- CVE-2019-59951 PoCMissing authorization vulnerability exists in EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X MKII…
- CVE-2019-59981 PoCBuffer overflow in PTP (Picture Transfer Protocol) of EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X…
- CVE-2019-59991 PoCBuffer overflow in PTP (Picture Transfer Protocol) of EOS series digital cameras (EOS-1D X firmware version 2.1.0 and earlier, EOS-1D X…