Unknown · CVSS Not scored
In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki access to make API calls for page metadata. In other words, the password hash can be retrieved even though it is not a publicly available field.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by providing a sufficiently long query string when POSTing to any valid cgi, txt, asp, or js file. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a race condition to replace the /tmp/repo.iso symlink by an attacker controlled ISO file, further privilege escalation may be possible.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe(). Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x0000000000002d7d.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e566.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e849.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000001172b0.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to crashes. When parsing input video, the program allocates a new buffer to parse an atom in the stream. The unhandled memory allocation failure causes a direct copy to a NULL pointer.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow while returning an error message to the user about failure to resolve a hostname during a ping or traceroute attempt. This allows an authenticated user to execute arbitrary code. The exploit can be exercised on the local intranet or remotely if remote administration is enabled.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an information leak, or possibly unspecified other impact.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a95b1.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9e7a.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9c2f.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for the setup wizard, allowing an unauthenticated user to execute arbitrary code. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as common optional libraries for PHP and Rust.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000024ed.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000c47ff.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard functionality, giving this attacker the ability to change configuration values, potentially leading to a denial of service. The request can be made on the local intranet or remotely if remote administration is enabled.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a9601.
Published Jul 4, 2019 · Updated Aug 4, 2024