CVE-2019-4132
IBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rather than receive a 404 error message. IBM X-Force ID: 158274.
Source: CVE-2019-4132
CVE-2019-4132
IBM Cloud Automation Manager 3.1.2 could allow a user to be impropertly redirected and obtain sensitive information rather than receive a 404 error message. IBM X-Force ID: 158274.
Source: CVE-2019-4132
CVE-2019-11476
An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the whoopsie process.
Source: CVE-2019-11476
CVE-2019-11500
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because ‘{$content}’ characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
Source: CVE-2019-11500
CVE-2019-15779
The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.
Source: CVE-2019-15779
CVE-2019-15745
The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses between the device and the app. The communication happens over UDP port 27431. An attacker on the local network can use the same key to encrypt and send commands to discover all smart plugs in a network, take over control of a device, and perform actions such as turning it on and off.
Source: CVE-2019-15745
CVE-2019-15781
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
Source: CVE-2019-15781
CVE-2019-15784
Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
Source: CVE-2019-15784
CVE-2019-15785
FontForge through 20190801 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c.
Source: CVE-2019-15785
CVE-2019-15788
Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
Source: CVE-2019-15788
CVE-2019-15786
ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket.
Source: CVE-2019-15786