Search Results (323438 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-16150 1 Fortinet 1 Forticlient 2024-11-21 5.5 Medium
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key.
CVE-2019-16148 1 Sakailms 1 Sakai 2024-11-21 6.1 Medium
Sakai through 12.6 allows XSS via a chat user name.
CVE-2019-16147 1 Liferay 1 Liferay Portal 2024-11-21 6.1 Medium
Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-taglib.
CVE-2019-16146 1 Getgophish 1 Gophish 2024-11-21 4.8 Medium
Gophish through 0.8.0 allows XSS via a username.
CVE-2019-16145 1 Padrinorb 1 Padrino-contrib 2024-11-21 6.1 Medium
The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
CVE-2019-16144 1 Generator-rs Project 1 Generator-rs 2024-11-21 7.5 High
An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and yield_ during API calls.
CVE-2019-16143 1 Blake2 1 Blake2-rust 2024-11-21 9.8 Critical
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes.
CVE-2019-16142 1 Renderdocs-rs Project 1 Renderdocs-rs 2024-11-21 9.8 Critical
An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable reference, which is incompatible with a multi-threaded application.
CVE-2019-16141 1 Once Cell Project 1 Once Cell 2024-11-21 7.5 High
An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
CVE-2019-16140 1 Isahc Project 1 Isahc 2024-11-21 9.8 Critical
An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion.
CVE-2019-16139 1 Compact Arena Project 1 Compact Arena 2024-11-21 9.8 Critical
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
CVE-2019-16138 1 Image-rs 1 Image 2024-11-21 9.8 Critical
An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len is called on an uninitialized vector, leading to a use-after-free and arbitrary code execution.
CVE-2019-16137 1 Spin-rs Project 1 Spin-rs 2024-11-21 7.5 High
An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclusion.
CVE-2019-16133 1 Weaver 1 Eteams Oa 2024-11-21 6.5 Medium
An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.
CVE-2019-16132 1 Phpok 1 Oklite 2024-11-21 6.5 Medium
An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.
CVE-2019-16131 1 Phpok 1 Oklite 2024-11-21 8.8 High
framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.
CVE-2019-16130 1 Hgw168cc 1 Yii-cms 2024-11-21 6.1 Medium
YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
CVE-2019-16129 1 Microchip 1 Cryptoauthlib 2024-11-21 6.8 Medium
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
CVE-2019-16128 1 Microchip 1 Cryptoauthlib 2024-11-21 6.8 Medium
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
CVE-2019-16127 1 Microchip 1 Advanced Software Framework 4 2024-11-21 9.1 Critical
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.