CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2020-3266

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI utility. The attacker must be authenticated to access the CLI utility. A successful exploit could allow the attacker to execute commands with root privileges.

    Published: 19 Mar 2020
    8.8
    High

    CVE-2014-2722

    Last Modified: 21 Nov 2024

    In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14876

    Last Modified: 21 Nov 2024

    In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. The access to b1 will trigger a null pointer dereference bug in case of a memory allocation failure.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14875

    Last Modified: 21 Nov 2024

    In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. The access of _x[0] will trigger a null pointer dereference bug in case of a memory allocation failure.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14874

    Last Modified: 21 Nov 2024

    In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. The access of _ x[0] will trigger a null pointer dereference bug in case of a memory allocation failure.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14878

    Last Modified: 21 Nov 2024

    In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. Accessing _x will trigger a null pointer dereference bug in case of a memory allocation failure.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14877

    Last Modified: 21 Nov 2024

    In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate big integers, however no check is performed to verify if the allocation succeeded or not. The access to _wds and _sign will trigger a null pointer dereference bug in case of a memory allocation failure.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14873

    Last Modified: 21 Nov 2024

    In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is performed to verify if the allocation succeeded or not. This will trigger a null pointer dereference bug in case of a memory allocation failure.

    Published: 19 Mar 2020
    —
    Unknown

    CVE-2019-5104

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-9013. Reason: This candidate is a duplicate of CVE-2019-9013. Notes: All CVE users should reference CVE-2019-9013 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Mar 2020
    6.1
    Medium

    CVE-2019-12416

    Last Modified: 21 Nov 2024

    we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.

    Published: 19 Mar 2020
    8.8
    High

    CVE-2020-10678

    Last Modified: 21 Nov 2024

    In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.

    Published: 19 Mar 2020
    6.1
    Medium

    CVE-2019-20522

    Last Modified: 21 Nov 2024

    ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.

    Published: 19 Mar 2020
    6.1
    Medium

    CVE-2019-20523

    Last Modified: 21 Nov 2024

    ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.

    Published: 19 Mar 2020
    6.1
    Medium

    CVE-2019-20527

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.

    Published: 19 Mar 2020
    6.1
    Medium

    CVE-2019-20524

    Last Modified: 21 Nov 2024

    ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

    Published: 19 Mar 2020
    9.8
    Critical

    CVE-2019-12130

    Last Modified: 21 Nov 2024

    In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

    Published: 19 Mar 2020
    9.8
    Critical

    CVE-2019-12129

    Last Modified: 21 Nov 2024

    In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

    Published: 19 Mar 2020
    9.8
    Critical

    CVE-2019-12128

    Last Modified: 21 Nov 2024

    In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

    Published: 19 Mar 2020
    6.3
    Medium

    CVE-2020-4205

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could allow an authenticated user to bypass security restrictions, and continue to access the server even after authentication certificates have been revolked. IBM X-Force ID: 174961.

    Published: 19 Mar 2020
    4.9
    Medium

    CVE-2020-4203

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.8 could potentially disclose highly sensitive information to a privileged user due to improper access controls. IBM X-Force ID: 174956.

    Published: 19 Mar 2020
    7.8
    High

    CVE-2020-10648

    Last Modified: 12 May 2026

    Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

    Published: 19 Mar 2020
    6.5
    Medium

    CVE-2019-14872

    Last Modified: 21 Nov 2024

    The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return value. This could result in NULL pointer dereference.

    Published: 19 Mar 2020
    7.5
    High

    CVE-2020-10663

    Last Modified: 21 Nov 2024

    The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.

    Published: 19 Mar 2020
    5.4
    Medium

    CVE-2019-16375

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5.0.37 and 6.0.x through 6.0.22. An attacker who is logged in as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent composes an answer to the original article.

    Published: 19 Mar 2020
    4
    Medium

    CVE-2020-5267

    Last Modified: 21 Nov 2024

    In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.

    Published: 19 Mar 2020
    4.3
    Medium

    CVE-2019-19677

    Last Modified: 21 Nov 2024

    arxes-tolina 3.0.0 allows User Enumeration.

    Published: 18 Mar 2020
    9.6
    Critical

    CVE-2019-19676

    Last Modified: 21 Nov 2024

    A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains malicious code. Other users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2020-10674

    Last Modified: 21 Nov 2024

    PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.

    Published: 18 Mar 2020
    6.5
    Medium

    CVE-2020-10365

    Last Modified: 21 Nov 2024

    LogicalDoc before 8.3.3 allows SQL Injection. LogicalDoc populates the list of available documents by querying the database. This list could be filtered by modifying some of the parameters. Some of them are not properly sanitized which could allow an authenticated attacker to perform arbitrary queries to the database.

    Published: 18 Mar 2020
    4.8
    Medium

    CVE-2020-7256

    Last Modified: 21 Nov 2024

    Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.

    Published: 18 Mar 2020
    4.8
    Medium

    CVE-2020-7258

    Last Modified: 21 Nov 2024

    Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.

    Published: 18 Mar 2020
    9.8
    Critical

    CVE-2020-9423

    Last Modified: 21 Nov 2024

    LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc provides a functionality to add documents. Those documents could then be used for multiple tasks, such as version control, shared among users, applying tags, etc. This functionality could be abused by an unauthenticated attacker to upload an arbitrary file in a restricted folder. This would lead to the executions of malicious commands with root privileges.

    Published: 18 Mar 2020
    7.8
    High

    CVE-2019-18979

    Last Modified: 21 Nov 2024

    Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.

    Published: 18 Mar 2020
    6.7
    Medium

    CVE-2020-10665

    Last Modified: 21 Nov 2024

    Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before 2.1.0.9, Docker Desktop for Windows Stable before 2.2.0.4, and Docker Desktop for Windows Edge before 2.2.2.0.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-20528

    Last Modified: 21 Nov 2024

    Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2019-3762

    Last Modified: 21 Nov 2024

    Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to impersonate a valid system to compromise the integrity of data.

    Published: 18 Mar 2020
    7.2
    High

    CVE-2019-18582

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to inject malicious report generation scripts in the server. This may lead to OS command execution as the regular user runs the DPA service on the affected system.

    Published: 18 Mar 2020
    7.2
    High

    CVE-2019-18581

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server missing authorization vulnerability in the REST API. A remote authenticated malicious user with administrative privileges may potentially exploit this vulnerability to alter the application’s allowable list of OS commands. This may lead to arbitrary OS command execution as the regular user runs the DPA service on the affected system.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-20512

    Last Modified: 21 Nov 2024

    Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-20511

    Last Modified: 21 Nov 2024

    ERPNext 11.1.47 allows blog?blog_category= Frame Injection.

    Published: 18 Mar 2020
    6.5
    Medium

    CVE-2019-12921

    Last Modified: 21 Nov 2024

    In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.

    Published: 18 Mar 2020
    8.8
    High

    CVE-2019-12769

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-12370

    Last Modified: 21 Nov 2024

    The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-12369

    Last Modified: 21 Nov 2024

    The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-12368

    Last Modified: 21 Nov 2024

    The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-12367

    Last Modified: 21 Nov 2024

    The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

    Published: 18 Mar 2020
    7.5
    High

    CVE-2019-20529

    Last Modified: 21 Nov 2024

    In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-12366

    Last Modified: 21 Nov 2024

    The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

    Published: 18 Mar 2020
    6.1
    Medium

    CVE-2019-12365

    Last Modified: 21 Nov 2024

    The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.

    Published: 18 Mar 2020
    9.1
    Critical

    CVE-2019-12131

    Last Modified: 21 Nov 2024

    An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected.

    Published: 18 Mar 2020