Show filters
398 Total Results
Displaying 271-280 of 398
Sort by:
Attacker Value
Unknown
CVE-2015-9517
Disclosure Date: October 23, 2019 (last updated February 08, 2025)
The Easy Digital Downloads (EDD) Manual Purchases extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
0
Attacker Value
Unknown
CVE-2019-12148
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into the device's admin web portal without providing any credentials. This affects /var/webconfig/gui/Webconfig.inc.php.
0
Attacker Value
Unknown
CVE-2019-12147
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that user to login to the system (either via the web interface or via SSH) to achieve complete compromise of the device. This affects /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt.
0
Attacker Value
Unknown
CVE-2019-17594
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
0
Attacker Value
Unknown
CVE-2019-17595
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
0
Attacker Value
Unknown
CVE-2019-17359
Disclosure Date: October 08, 2019 (last updated November 08, 2023)
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
0
Attacker Value
Unknown
CVE-2019-10097
Disclosure Date: September 26, 2019 (last updated November 08, 2023)
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.
0
Attacker Value
Unknown
CVE-2019-5482
Disclosure Date: September 16, 2019 (last updated November 08, 2023)
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
0
Attacker Value
Unknown
CVE-2019-5481
Disclosure Date: September 16, 2019 (last updated November 08, 2023)
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
0
Attacker Value
Unknown
CVE-2019-12402
Disclosure Date: August 30, 2019 (last updated November 08, 2023)
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
0