Show filters
398 Total Results
Displaying 281-290 of 398
Sort by:
Attacker Value
Unknown

CVE-2019-15775

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
0
Attacker Value
Unknown

CVE-2015-9371

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
Manual Purchases Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
0
Attacker Value
Unknown

CVE-2019-15548

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.
0
Attacker Value
Unknown

CVE-2019-15546

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.
0
Attacker Value
Unknown

CVE-2019-15547

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.
0
Attacker Value
Unknown

CVE-2019-14422

Disclosure Date: August 15, 2019 (last updated November 27, 2024)
An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used to open remote workbooks without protection from macro security settings to execute arbitrary code. A tsvncmd:command:diff?path:[file1]?path2:[file2] URI will execute a customised diff on [file1] and [file2] based on the file extension. For xls files, it will execute the script diff-xls.js using wscript, which will open the two files for analysis without any macro security warning. An attacker can exploit this by putting a macro virus in a network drive, and force the victim to open the workbooks and execute the macro inside.
0
Attacker Value
Unknown

CVE-2019-0197

Disclosure Date: June 11, 2019 (last updated November 08, 2023)
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled it for https: and did not set "H2Upgrade on" are unaffected by this issue.
Attacker Value
Unknown

CVE-2019-5958

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2019-5957

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2019-0227

Disclosure Date: May 01, 2019 (last updated November 08, 2023)
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.