CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2020-5211

    Last Modified: 21 Nov 2024

    In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

    Published: 28 Jan 2020
    5
    Medium

    CVE-2020-5212

    Last Modified: 21 Nov 2024

    In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

    Published: 28 Jan 2020
    5
    Medium

    CVE-2020-5213

    Last Modified: 21 Nov 2024

    In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

    Published: 28 Jan 2020
    5
    Medium

    CVE-2020-5214

    Last Modified: 21 Nov 2024

    In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

    Published: 28 Jan 2020
    5
    Medium

    CVE-2020-5209

    Last Modified: 21 Nov 2024

    In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.

    Published: 28 Jan 2020
    5
    Medium

    CVE-2020-5210

    Last Modified: 21 Nov 2024

    In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to influence command line options. Users should upgrade to NetHack 3.6.5.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2020-8112

    Last Modified: 21 Nov 2024

    opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2020-1940

    Last Modified: 21 Nov 2024

    The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials object but does not remove it upon processing during the first phase of the authentication. In combination with additional, independent authentication mechanisms, this may lead to the new password being disclosed.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2012-6609

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2012-6610

    Last Modified: 21 Nov 2024

    Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2020-8086

    Last Modified: 21 Nov 2024

    The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2013-4861

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.

    Published: 28 Jan 2020
    8.1
    High

    CVE-2013-4862

    Last Modified: 21 Nov 2024

    MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2013-4863

    Last Modified: 21 Nov 2024

    The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to port_49451/upnp/control/hag.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2013-4864

    Last Modified: 21 Nov 2024

    MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2013-4865

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.

    Published: 28 Jan 2020
    5.9
    Medium

    CVE-2013-0294

    Last Modified: 21 Nov 2024

    packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2014-2898

    Last Modified: 21 Nov 2024

    wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2014-2897

    Last Modified: 21 Nov 2024

    The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMAC, which triggers an out-of-bounds read.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2014-2896

    Last Modified: 21 Nov 2024

    The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.

    Published: 28 Jan 2020
    7
    High

    CVE-2014-2906

    Last Modified: 21 Nov 2024

    The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.

    Published: 28 Jan 2020
    7
    High

    CVE-2014-3856

    Last Modified: 21 Nov 2024

    The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2014-2914

    Last Modified: 21 Nov 2024

    fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2013-4582

    Last Modified: 21 Nov 2024

    The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to include information from local files into the metadata of a Git repository via the web interface.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2013-4583

    Last Modified: 21 Nov 2024

    The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2013-6451

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2013-6455

    Last Modified: 21 Nov 2024

    The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of a page.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2013-2571

    Last Modified: 21 Nov 2024

    Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

    Published: 28 Jan 2020
    5.5
    Medium

    CVE-2012-6114

    Last Modified: 21 Nov 2024

    The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2013-1895

    Last Modified: 21 Nov 2024

    The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2014-2581

    Last Modified: 21 Nov 2024

    Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2014-3445

    Last Modified: 21 Nov 2024

    backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.

    Published: 28 Jan 2020
    5.4
    Medium

    CVE-2020-7934

    Last Modified: 21 Nov 2024

    In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyAccountPortlet are all vulnerable to a persistent XSS issue. Any user can modify these fields with a particular XSS payload, and it will be stored in the database. The payload will then be rendered when a user utilizes the search feature to search for other users (i.e., if a user with modified fields occurs in the search results). This issue was fixed in Liferay Portal CE version 7.3.0 GA1.

    Published: 28 Jan 2020
    7.2
    High

    CVE-2020-7799

    Last Modified: 21 Nov 2024

    An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute commands on the underlying operating system by abusing freemarker.template.utility.Execute in the Apache FreeMarker engine that processes custom templates.

    Published: 28 Jan 2020
    7.4
    High

    CVE-2020-5523

    Last Modified: 21 Nov 2024

    Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2020-7998

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.

    Published: 28 Jan 2020
    6.1
    Medium

    CVE-2020-7997

    Last Modified: 21 Nov 2024

    ASUS WRT-AC66U 3 RT 3.0.0.4.372_67 devices allow XSS via the Client Name field to the Parental Control feature.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2019-5472

    Last Modified: 21 Nov 2024

    An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2019-5470

    Last Modified: 21 Nov 2024

    An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2019-15578

    Last Modified: 21 Nov 2024

    An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). The path of a private project, that used to be public, would be disclosed in the unsubscribe email link of issues and merge requests.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2019-15579

    Last Modified: 21 Nov 2024

    An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) where the assignee(s) of a confidential issue in a private project would be disclosed to a guest via milestones.

    Published: 28 Jan 2020
    8.8
    High

    CVE-2019-5468

    Last Modified: 21 Nov 2024

    An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2019-15581

    Last Modified: 21 Nov 2024

    An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a project owner or maintainer to see the members of any private group via merge request approval rules.

    Published: 28 Jan 2020
    4.3
    Medium

    CVE-2019-5466

    Last Modified: 21 Nov 2024

    An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.

    Published: 28 Jan 2020
    5.3
    Medium

    CVE-2019-15582

    Last Modified: 21 Nov 2024

    An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that allowed a maintainer to add any private group to a protected environment.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2019-15590

    Last Modified: 21 Nov 2024

    An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration

    Published: 28 Jan 2020
    6.5
    Medium

    CVE-2019-5474

    Last Modified: 21 Nov 2024

    An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval rules to be overridden without appropriate permissions.

    Published: 28 Jan 2020
    4.3
    Medium

    CVE-2019-5465

    Last Modified: 21 Nov 2024

    An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which could result in disclosure of the newly created issue ID.

    Published: 28 Jan 2020
    7.5
    High

    CVE-2019-15583

    Last Modified: 21 Nov 2024

    An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). When an issue was moved to a public project from a private one, the associated private labels and the private project namespace would be disclosed through the GitLab API.

    Published: 28 Jan 2020
    9.8
    Critical

    CVE-2019-5464

    Last Modified: 21 Nov 2024

    A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

    Published: 28 Jan 2020