Show filters
546 Total Results
Displaying 311-320 of 546
Sort by:
Attacker Value
Unknown
CVE-2019-8254
Disclosure Date: December 19, 2019 (last updated November 27, 2024)
Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2019-8253
Disclosure Date: December 19, 2019 (last updated November 27, 2024)
Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2019-13939
Disclosure Date: November 12, 2019 (last updated February 21, 2025)
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus Source Code (All versions). By sending specially crafted DHCP packets to a device where the DHCP client is enabled, an attacker could change the IP address of the device to an invalid value.
0
Attacker Value
Unknown
CVE-2019-18178
Disclosure Date: November 04, 2019 (last updated November 27, 2024)
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), but it is reused to flush modified file content from the cache to disk by the function FF_FlushCache().
0
Attacker Value
Unknown
CVE-2019-13120
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2019-15747
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Systemadministrator role due to insufficient checks on the server side.
0
Attacker Value
Unknown
CVE-2019-15746
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.
0
Attacker Value
Unknown
CVE-2019-15749
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.
0
Attacker Value
Unknown
CVE-2019-15750
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
0
Attacker Value
Unknown
CVE-2019-15751
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by uploading a SCORM file with an executable extension. This allows an unauthenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to the web root of the application.
0