Search Results (327220 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-20201 1 Ezxml Project 1 Ezxml 2024-11-21 6.5 Medium
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.
CVE-2019-20200 1 Ezxml Project 1 Ezxml 2024-11-21 6.5 Medium
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buffer over-read in the "normalize line endings" feature.
CVE-2019-20199 1 Ezxml Project 1 Ezxml 2024-11-21 6.5 Medium
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dereference while running strlen() on a NULL pointer.
CVE-2019-20198 1 Ezxml Project 1 Ezxml 2024-11-21 6.5 Medium
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file.
CVE-2019-20197 1 Nagios 1 Nagios Xi 2024-11-21 8.8 High
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
CVE-2019-20191 1 Sync 3 Oxygen Xml Author, Oxygen Xml Developer, Oxygen Xml Editor 2024-11-21 7.5 High
Oxygen XML Editor 21.1.1 allows XXE to read any file.
CVE-2019-20184 1 Keepass 1 Keepass 2024-11-21 7.8 High
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
CVE-2019-20183 1 Employee Records System Project 1 Employee Records System 2024-11-21 7.2 High
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.
CVE-2019-20182 1 Fooplugins 1 Foogallery 2024-11-21 4.8 Medium
The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
CVE-2019-20181 1 Getawesomesupport 1 Awesome Support 2024-11-21 4.8 Medium
The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
CVE-2019-20180 1 Tablepress 1 Tablepress 2024-11-21 6.8 Medium
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disputes this issue and argues that this responsibility lies with the application that opens the CSV file and not TablePress.
CVE-2019-20179 1 Soplanning 1 Soplanning 2024-11-21 8.8 High
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
CVE-2019-20178 1 Peel 1 Peel Shopping 2024-11-21 6.5 Medium
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
CVE-2019-20176 2 Fedoraproject, Pureftpd 2 Fedora, Pure-ftpd 2024-11-21 7.5 High
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CVE-2019-20175 1 Qemu 1 Qemu 2024-11-21 7.5 High
An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a multiple of 512 (the size of a sector). NOTE: a member of the QEMU security team disputes the significance of this issue because a "privileged guest user has many ways to cause similar DoS effect, without triggering this assert.
CVE-2019-20174 1 Auth0 1 Lock 2024-11-21 6.1 Medium
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
CVE-2019-20173 1 Auth0 1 Login By Auth0 2024-11-21 6.1 Medium
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
CVE-2019-20172 1 Serenityos 1 Serenityos 2024-11-21 7.8 High
Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only virtual address space, which allows local users to gain privileges by overwriting a return address that was found on the kernel stack.
CVE-2019-20170 2 Debian, Gpac 2 Debian Linux, Gpac 2024-11-21 5.5 Medium
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.
CVE-2019-20169 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trak_Read() in isomedia/box_code_base.c.