Month: June 2019
-
CVE-2019-13112 – A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allow …
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash …
-
CVE-2019-13111 – A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to c …
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation …
-
CVE-2019-13110 – A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0. …
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of …
-
CVE-2019-13109 – An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of servic …
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because …
-
CVE-2019-13108 – An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of servic …
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because …
-
CVE-2019-13107 – Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, …
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and …
-
CVE-2018-20849 – Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI. …
Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ …
-
CVE-2018-20848 – Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_aff …
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in …
-
CVE-2019-13086 – core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injecti …
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header …
-
CVE-2019-13085 – XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa. …
XnView Classic 2.48 has a User Mode Write AV starting at …
-
CVE-2019-13084 – XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739. …
XnView Classic 2.48 has a User Mode Write AV starting at …
-
CVE-2019-13083 – XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a. …
XnView Classic 2.48 has a User Mode Write AV starting at …
●●●