Show filters
321 Total Results
Displaying 161-170 of 321
Sort by:
Attacker Value
Unknown

CVE-2019-9842

Disclosure Date: June 14, 2019 (last updated November 27, 2024)
madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in app_code/handlers/PostHandler.cs writes a decoded base64 string to a file without validating the extension.
0
Attacker Value
Unknown

CVE-2019-12110

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in upnpredirect.c.
0
Attacker Value
Unknown

CVE-2019-12106

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
0
Attacker Value
Unknown

CVE-2019-12111

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
Attacker Value
Unknown

CVE-2019-12107

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprintf return value.
0
Attacker Value
Unknown

CVE-2019-12108

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port.
0
Attacker Value
Unknown

CVE-2019-12109

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port.
0
Attacker Value
Unknown

CVE-2019-9845

Disclosure Date: April 16, 2019 (last updated November 27, 2024)
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.
0
Attacker Value
Unknown

CVE-2019-9765

Disclosure Date: March 14, 2019 (last updated November 27, 2024)
In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.
0
Attacker Value
Unknown

CVE-2018-19861

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.
0