Security News

Vuln: Oracle Java SE CVE-2019-2684 Remote Security Vulnerability

SecurityFocus Vulnerabilities - Mon, 07/01/2019 - 00:00
Oracle Java SE CVE-2019-2684 Remote Security Vulnerability
Categories: Security News

CVE-2019-13117

National Vulnerability Database - Sun, 06/30/2019 - 22:15
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
Categories: Security News

CVE-2019-13118

National Vulnerability Database - Sun, 06/30/2019 - 22:15
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Categories: Security News

CVE-2019-13109 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
Categories: Security News

CVE-2019-13110 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
Categories: Security News

CVE-2019-13111 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.
Categories: Security News

CVE-2019-13112 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
Categories: Security News

CVE-2019-13113 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
Categories: Security News

CVE-2019-13114 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
Categories: Security News

CVE-2019-13108 (exiv2)

National Vulnerability Database - Sun, 06/30/2019 - 19:15
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.
Categories: Security News

CVE-2019-13107

National Vulnerability Database - Sun, 06/30/2019 - 18:15
Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c
Categories: Security News

CVE-2018-20848

National Vulnerability Database - Sun, 06/30/2019 - 15:15
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.
Categories: Security News

CVE-2018-20849

National Vulnerability Database - Sun, 06/30/2019 - 15:15
Arastta eCommerce 1.6.2 is vulnerable to XSS via the PATH_INFO to the login/ URI.
Categories: Security News

CVE-2019-13086

National Vulnerability Database - Sun, 06/30/2019 - 13:15
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
Categories: Security News

CVE-2019-13082

National Vulnerability Database - Sun, 06/30/2019 - 12:15
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.
Categories: Security News

CVE-2019-13083

National Vulnerability Database - Sun, 06/30/2019 - 12:15
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.
Categories: Security News

CVE-2019-13084

National Vulnerability Database - Sun, 06/30/2019 - 12:15
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739.
Categories: Security News

CVE-2019-13085

National Vulnerability Database - Sun, 06/30/2019 - 12:15
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa.
Categories: Security News

CVE-2019-11821

National Vulnerability Database - Sun, 06/30/2019 - 11:15
SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.
Categories: Security News

CVE-2019-11822

National Vulnerability Database - Sun, 06/30/2019 - 11:15
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.
Categories: Security News

Pages