ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-15151
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

NVD description · AI analysis pending
9.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2019-14734
+2 in the same advisory: …14733 …14732
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

NVD description · AI analysis pending
8.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2019-14692
+2 in the same advisory: …14690 …14691
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

NVD description · AI analysis pending
8.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2018-1000883
Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added.

Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.

NVD description · AI analysis pending
6.51%
  • plug project plug
CVE-2018-17825
An issue was discovered in AdPlug 2.3.1.

An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.

NVD description · AI analysis pending
9.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2017-1000053
+1 in the same advisory: …1000052
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.

Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.

NVD description · AI analysis pending
8.1
group max
2%
  • plug project plug