Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-14 CVE-2019-17540 Out-of-bounds Write vulnerability in multiple products
ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.
network
low complexity
imagemagick debian CWE-787
8.8
2019-10-14 CVE-2019-17501 OS Command Injection vulnerability in Centreon 19.04.0
Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen).
network
low complexity
centreon CWE-78
8.8
2019-10-13 CVE-2019-17538 Path Traversal vulnerability in Jnoj Jiangnan Online Judge 0.8.0
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
network
low complexity
jnoj CWE-22
7.5
2019-10-13 CVE-2019-17537 Path Traversal vulnerability in Jnoj Jiangnan Online Judge 0.8.0
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
network
low complexity
jnoj CWE-22
7.5
2019-10-13 CVE-2019-17534 Use After Free vulnerability in Libvips
vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifGetImageDesc call, leading to a use-after-free.
network
low complexity
libvips CWE-416
8.8
2019-10-13 CVE-2019-17533 Use of Uninitialized Resource vulnerability in multiple products
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
network
low complexity
matio-project debian CWE-908
8.2
2019-10-12 CVE-2019-17532 Missing Authentication for Critical Function vulnerability in Belkin Wemo Switch 28B Firmware Wemoww2.00.11057.Pvtowrtsns
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices.
network
low complexity
belkin CWE-306
7.5
2019-10-12 CVE-2019-17530 Out-of-bounds Read vulnerability in Axiosys Bento4 1.5.1.0
An issue was discovered in Bento4 1.5.1.0.
local
low complexity
axiosys CWE-125
7.8
2019-10-12 CVE-2019-17529 Out-of-bounds Read vulnerability in Axiosys Bento4 1.5.1.0
An issue was discovered in Bento4 1.5.1.0.
local
low complexity
axiosys CWE-125
7.8
2019-10-12 CVE-2019-17528 Unspecified vulnerability in Axiosys Bento4 1.5.1.0
An issue was discovered in Bento4 1.5.1.0.
network
low complexity
axiosys
7.5