CVE-2019-7000 to CVE-2019-7999
185 CVEs with public proof-of-concept exploits.
- CVE-2019-70042 PoCsAvaya IP Office XSS Vulnerability
- CVE-2019-70691 PoCAdobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and…
- CVE-2019-71392 PoCsAn unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which causes sensitive…
- CVE-2019-71462 PoCsIn elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage…
- CVE-2019-71471 PoCA buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted asm input can…
- CVE-2019-71481 PoCAn attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote…
- CVE-2019-71491 PoCA heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted…
- CVE-2019-71501 PoCAn issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due…
- CVE-2019-71511 PoCA NULL pointer dereference was discovered in wasm::Module::getFunctionOrNull in wasm/wasm.cpp in Binaryen 1.38.22. A crafted input can…
- CVE-2019-71521 PoCA heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling…
- CVE-2019-71531 PoCA NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling…
- CVE-2019-71541 PoCThe main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an…
- CVE-2019-71561 PoCIn libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero.
- CVE-2019-71641 PoCSQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
- CVE-2019-71811 PoCBuffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the program.
- CVE-2019-71925 PoCsKEVThis improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these…
- CVE-2019-71931 PoCKEVThis improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability,…
- CVE-2019-71942 PoCsKEVThis external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the…
- CVE-2019-71953 PoCsKEVThis external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the…
- CVE-2019-72131 PoCSmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary files or could…
- CVE-2019-72146 PoCsSmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands…
- CVE-2019-72161 PoCAn issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user to upload any type…
- CVE-2019-72192 PoCsUnauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued…
- CVE-2019-72231 PoCInvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the…
- CVE-2019-72262 PoCsThe ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to…
- CVE-2019-72272 PoCsIn the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use…
- CVE-2019-72282 PoCsThe ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate…
- CVE-2019-72292 PoCsThe ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card…
- CVE-2019-72302 PoCsThe ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the…
- CVE-2019-72312 PoCsThe ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is…
- CVE-2019-72322 PoCsThe ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value…
- CVE-2019-72331 PoCIn libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.
- CVE-2019-723811 PoCsKEVSonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
- CVE-2019-72491 PoCIn Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one…
- CVE-2019-72543 PoCsLinear eMerge E3-Series devices allow File Inclusion.
- CVE-2019-72553 PoCsLinear eMerge E3-Series devices allow XSS.
- CVE-2019-72567 PoCsKEVLinear eMerge E3-Series devices allow Command Injections.
- CVE-2019-72572 PoCsLinear eMerge E3-Series devices allow Unrestricted File Upload.
- CVE-2019-72581 PoCLinear eMerge E3-Series devices allow Privilege Escalation.
- CVE-2019-72591 PoCLinear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
- CVE-2019-72611 PoCLinear eMerge E3-Series devices have Hard-coded Credentials.
- CVE-2019-72622 PoCsLinear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
- CVE-2019-72652 PoCsLinear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
- CVE-2019-72671 PoCLinear eMerge 50P/5000P devices allow Cookie Path Traversal.
- CVE-2019-72681 PoCLinear eMerge 50P/5000P devices allow Unauthenticated File Upload.
- CVE-2019-72692 PoCsLinear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
- CVE-2019-72722 PoCsOptergy Proton/Enterprise devices allow Username Disclosure.
- CVE-2019-72731 PoCOptergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
- CVE-2019-72742 PoCsOptergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
- CVE-2019-72751 PoCOptergy Proton/Enterprise devices allow Open Redirect.
- CVE-2019-72763 PoCsOptergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
- CVE-2019-72861 PoCKEVA memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3…
- CVE-2019-72951 PoCtypora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
- CVE-2019-72961 PoCtypora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
- CVE-2019-72971 PoCAn issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to…
- CVE-2019-72981 PoCAn issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allows attackers to…
- CVE-2019-73002 PoCsArtica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/settings.inc ldap_admin…
- CVE-2019-73011 PoCZen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the…
- CVE-2019-73031 PoCSnapd seccomp filter TIOCSTI ioctl bypass
- CVE-2019-730411 PoCsLocal privilege escalation via snapd socket
- CVE-2019-73061 PoCByobu apport hook uploads user's ~/.screenrc
- CVE-2019-73071 PoCApport contains a TOCTTOU vulnerability when reading the users ~/.apport-ignore.xml
- CVE-2019-731426 PoCsliblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which…
- CVE-2019-73152 PoCsGenie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web…
- CVE-2019-73161 PoCAn issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.
- CVE-2019-73232 PoCsGUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows…
- CVE-2019-73421 PoCPOST - Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code via a…
- CVE-2019-73561 PoCSubrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
- CVE-2019-73571 PoCSubrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
- CVE-2019-73832 PoCsAn issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell…
- CVE-2019-73842 PoCsAn authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON…
- CVE-2019-73853 PoCsAn authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and HT803G GPON…
- CVE-2019-73864 PoCsA Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When…
- CVE-2019-73881 PoCAn issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing…
- CVE-2019-73891 PoCAn issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing…
- CVE-2019-73901 PoCAn issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing…
- CVE-2019-73912 PoCsZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
- CVE-2019-74002 PoCsRukovoditel before 2.4.1 allows XSS.
- CVE-2019-74021 PoCAn issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This…
- CVE-2019-74031 PoCAn issue was discovered in PHPMyWind 5.5. It allows remote attackers to delete arbitrary folders via an…
- CVE-2019-74041 PoCAn issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file via an HTTP request…
- CVE-2019-74091 PoCMultiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script…
- CVE-2019-74111 PoCMultiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to…
- CVE-2019-74121 PoCThe PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.
- CVE-2019-74162 PoCsXSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm"…
- CVE-2019-74172 PoCsXSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by…
- CVE-2019-74182 PoCsXSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag,…
- CVE-2019-74192 PoCsXSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters:…
- CVE-2019-74202 PoCsXSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in…
- CVE-2019-74212 PoCsXSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.login/gnb/loginView.sws" in multiple…
- CVE-2019-74222 PoCsXSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp"…
- CVE-2019-74232 PoCsXSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in…
- CVE-2019-74242 PoCsXSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the…
- CVE-2019-74252 PoCsXSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp"…
- CVE-2019-74262 PoCsXSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp"…
- CVE-2019-74272 PoCsXSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp"…
- CVE-2019-74291 PoCPHP Scripts Mall Property Rental Software 2.1.4 has directory traversal via a direct request for a listing of an uploads directory such as…
- CVE-2019-74301 PoCPHP Scripts Mall Image Sharing Script 1.3.4 has HTML injection via the Search Bar.
- CVE-2019-74311 PoCPHP Scripts Mall Image Sharing Script 1.3.4 has directory traversal via a direct request for a listing of an uploads directory.
- CVE-2019-74321 PoCPHP Scripts Mall Rental Bike Script 2.0.3 has HTML injection via the STREET field in the Profile Edit section.
- CVE-2019-74331 PoCPHP Scripts Mall Rental Bike Script 2.0.3 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.
- CVE-2019-74341 PoCPHP Scripts Mall Rental Bike Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory.
- CVE-2019-74351 PoCPHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form.
- CVE-2019-74361 PoCPHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory.
- CVE-2019-74371 PoCPHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field.
- CVE-2019-74384 PoCscgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter.
- CVE-2019-74393 PoCscgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
- CVE-2019-74402 PoCsJioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_Setting request to…
- CVE-2019-74412 PoCscgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an…
- CVE-2019-74422 PoCsAn XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows…
- CVE-2019-74811 PoCKEVVulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity…
- CVE-2019-74822 PoCsStack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This…
- CVE-2019-74881 PoCWeak default password cause vulnerability in SonicWall Email Security appliance which leads to attacker gain access to appliance database.…
- CVE-2019-74891 PoCA vulnerability in SonicWall Email Security appliance allow an unauthenticated user to perform remote code execution. This vulnerability…
- CVE-2019-75371 PoCAn issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary…
- CVE-2019-75412 PoCsRukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
- CVE-2019-75431 PoCIn KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.
- CVE-2019-75481 PoCSQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
- CVE-2019-75521 PoCAn issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due…
- CVE-2019-75531 PoCPHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
- CVE-2019-75541 PoCAn issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-results.php d2 parameter.
- CVE-2019-75641 PoCAn issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID…
- CVE-2019-75661 PoCCSZ CMS 1.1.8 has CSRF via admin/users/new/add.
- CVE-2019-75681 PoCAn issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an…
- CVE-2019-75691 PoCAn issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator…
- CVE-2019-75701 PoCA CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
- CVE-2019-75721 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
- CVE-2019-75731 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c…
- CVE-2019-75741 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in…
- CVE-2019-75751 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.
- CVE-2019-75761 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c…
- CVE-2019-75771 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.
- CVE-2019-75781 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.
- CVE-2019-75791 PoCAn issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to browse a confidential…
- CVE-2019-75802 PoCsThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter…
- CVE-2019-75812 PoCsThe parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a…
- CVE-2019-75822 PoCsThe readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file…
- CVE-2019-75881 PoCexacqVision Enterprise System Manager (ESM) privilege escalation
- CVE-2019-75901 PoCexacqVision Server Unquoted Service Path
- CVE-2019-760915 PoCsKEVKibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to…
- CVE-2019-76161 PoCKibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion…
- CVE-2019-76291 PoCStack-based buffer overflow in the strip_vt102_codes function in TinTin++ 2.01.6 and WinTin++ 2.01.6 allows remote attackers to execute…
- CVE-2019-76321 PoCLifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell…
- CVE-2019-76351 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
- CVE-2019-76361 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.
- CVE-2019-76371 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.
- CVE-2019-76381 PoCSDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
- CVE-2019-76421 PoCD-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can remotely obtain…
- CVE-2019-76462 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package Name" field via…
- CVE-2019-76511 PoCEPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device Characteristics…
- CVE-2019-76521 PoCTheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the vulnerability, an…
- CVE-2019-76561 PoCA privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges…
- CVE-2019-76621 PoCAn assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This allows remote…
- CVE-2019-76631 PoCAn Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10,…
- CVE-2019-76641 PoCIn elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check.…
- CVE-2019-76651 PoCIn elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted…
- CVE-2019-76662 PoCsPrima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash value of the password,…
- CVE-2019-76671 PoCPrima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable name, and an attacker…
- CVE-2019-76691 PoCPrima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote…
- CVE-2019-76702 PoCsPrima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended…
- CVE-2019-76712 PoCsPrima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being returned to the user,…
- CVE-2019-76741 PoCAn issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password, considered…
- CVE-2019-76751 PoCAn issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleartext HTTP with…
- CVE-2019-76841 PoCinxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is…
- CVE-2019-76871 PoCcgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page parameter. No sanitization…
- CVE-2019-76931 PoCAxios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations, the XSS would be…
- CVE-2019-76971 PoCAn issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to…
- CVE-2019-76981 PoCAn issue was discovered in AP4_Array<AP4_CttsTableEntry>::EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input…
- CVE-2019-76991 PoCA heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could…
- CVE-2019-77001 PoCA heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm…
- CVE-2019-77011 PoCA heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen 1.38.22. A…
- CVE-2019-77021 PoCA NULL pointer dereference was discovered in wasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in Binaryen 1.38.22. A…
- CVE-2019-77031 PoCIn Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote attackers could…
- CVE-2019-77041 PoCwasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as…
- CVE-2019-77112 PoCsAn issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented shell command…
- CVE-2019-77181 PoCAn issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup function to execute…
- CVE-2019-77301 PoCMyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=databases URI.
- CVE-2019-77371 PoCA CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.
- CVE-2019-77381 PoCC.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
- CVE-2019-77451 PoCJioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi…
- CVE-2019-77461 PoCJioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_auth type=getuser…
- CVE-2019-77512 PoCsA directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI…
- CVE-2019-77552 PoCsIn webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement files, resulting in…
- CVE-2019-77611 PoCAdobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and…
- CVE-2019-78392 PoCsColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability.…