Show filters
185 Total Results
Displaying 111-120 of 185
Sort by:
Attacker Value
Unknown
CVE-2019-20089
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculation.
0
Attacker Value
Unknown
CVE-2019-12308
Disclosure Date: June 03, 2019 (last updated November 08, 2023)
An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL value displayed by the AdminURLFieldWidget displays the provided value without validating it as a safe URL. Thus, an unvalidated value stored in the database, or a value provided as a URL query parameter payload, could result in an clickable JavaScript link.
0
Attacker Value
Unknown
CVE-2019-6975
Disclosure Date: February 11, 2019 (last updated November 08, 2023)
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() function.
0
Attacker Value
Unknown
CVE-2019-3498
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing (in a 404 error page) if a user fails to recognize that a crafted URL has malicious content.
0
Attacker Value
Unknown
CVE-2018-18699
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
An issue was discovered in GoPro gpmf-parser 1.2.1. There is an out-of-bounds write in OpenMP4Source in GPMF_mp4reader.c.
0
Attacker Value
Unknown
CVE-2018-18190
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
An issue was discovered in GoPro gpmf-parser before 1.2.1. There is a divide-by-zero error in GPMF_ScaledData in GPMF_parser.c.
0
Attacker Value
Unknown
CVE-2018-16984
Disclosure Date: October 02, 2018 (last updated November 27, 2024)
An issue was discovered in Django 2.1 before 2.1.2, in which unprivileged users can read the password hashes of arbitrary accounts. The read-only password widget used by the Django Admin to display an obfuscated password hash was bypassed if a user has only the "view" permission (new in Django 2.1), resulting in display of the entire password hash to those users. This may result in a vulnerability for sites with legacy user accounts using insecure hashes.
0
Attacker Value
Unknown
CVE-2018-14574
Disclosure Date: August 03, 2018 (last updated November 27, 2024)
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
0
Attacker Value
Unknown
CVE-2018-13026
Disclosure Date: June 30, 2018 (last updated November 26, 2024)
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Type.
0
Attacker Value
Unknown
CVE-2018-13011
Disclosure Date: June 29, 2018 (last updated November 26, 2024)
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Validate.
0