Search Results (325042 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-17417 1 Pbootcms 1 Pbootcms 2024-11-21 4.8 Medium
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
CVE-2019-17415 1 Upredsun 1 File Sharing Wizard 2024-11-21 9.8 Critical
A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331.
CVE-2019-17414 1 Vino Project 1 Vino 2024-11-21 7.5 High
tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.
CVE-2019-17409 1 Open-emr 1 Openemr 2024-11-21 6.1 Medium
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
CVE-2019-17408 1 Zzzcms 1 Zzzphp 2024-11-21 9.8 Critical
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
CVE-2019-17406 1 Nokia 1 Impact 2024-11-21 5.3 Medium
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
CVE-2019-17405 1 Nokia 1 Impact 2024-11-21 6.1 Medium
Nokia IMPACT < 18A: has Reflected self XSS
CVE-2019-17404 1 Nokia 1 Impact 2024-11-21 4.3 Medium
Nokia IMPACT < 18A: allows full path disclosure
CVE-2019-17403 1 Nokia 1 Impact 2024-11-21 8.8 High
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
CVE-2019-17402 4 Canonical, Debian, Exiv2 and 1 more 4 Ubuntu Linux, Debian Linux, Exiv2 and 1 more 2024-11-21 6.5 Medium
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.
CVE-2019-17401 1 Liblnk Project 1 Liblnk 2024-11-21 3.3 Low
libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue than CVE-2019-17264. NOTE: the vendor has disputed this as described in the GitHub issue
CVE-2019-17400 2 Redhat, Universal Office Converter Project 2 Enterprise Linux, Universal Office Converter 2024-11-21 7.5 High
The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion.
CVE-2019-17399 1 Joomlashack 1 Shack Forms Pro 2024-11-21 9.8 Critical
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
CVE-2019-17398 1 Darkhorse 1 Dark Horse Comics 2024-11-21 9.8 Critical
In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17397 1 Doordash 1 Doordash 2024-11-21 9.8 Critical
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17396 1 Powerschool 1 Powerschool Mobile 2024-11-21 9.8 Critical
In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17395 1 Rapidgator 1 Rapidgator 2024-11-21 9.8 Critical
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17394 1 Seesaw 1 Parent And Family 2024-11-21 9.8 Critical
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17393 1 Tomedo 1 Server 2024-11-21 9.8 Critical
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.
CVE-2019-17392 1 Progress 1 Sitefinity 2024-11-21 9.8 Critical
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.