CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-6618

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6619

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6620

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6621

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6622

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6623

    Last Modified: 21 Nov 2024

    stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2011-5266

    Last Modified: 21 Nov 2024

    Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2011-5250

    Last Modified: 21 Nov 2024

    Snare for Linux before 1.7.0 has CSRF in the web interface.

    Published: 8 Jan 2020
    7.5
    High

    CVE-2011-5247

    Last Modified: 21 Nov 2024

    Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2011-5018

    Last Modified: 21 Nov 2024

    Koala Framework before 2011-11-21 has XSS via the request_uri parameter.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2019-17001

    Last Modified: 21 Nov 2024

    A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document (cross-site scripting). This is a separate bypass from CVE-2019-17000.*Note: This flaw only affected Firefox 69 and was not present in earlier versions.*. This vulnerability affects Firefox < 70.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2019-17025

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2019-17020

    Last Modified: 21 Nov 2024

    If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability affects Firefox < 72.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2019-17019

    Last Modified: 21 Nov 2024

    When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 72.

    Published: 8 Jan 2020
    5.3
    Medium

    CVE-2019-17018

    Last Modified: 21 Nov 2024

    When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerability affects Firefox < 72.

    Published: 8 Jan 2020
    4.3
    Medium

    CVE-2019-17002

    Last Modified: 21 Nov 2024

    If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-6609

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2020-6610

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2020-6611

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.

    Published: 8 Jan 2020
    8.1
    High

    CVE-2020-6612

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.

    Published: 8 Jan 2020
    8.1
    High

    CVE-2020-6613

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

    Published: 8 Jan 2020
    8.1
    High

    CVE-2020-6614

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2020-6615

    Last Modified: 21 Nov 2024

    GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl).

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2019-17000

    Last Modified: 21 Nov 2024

    An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2019-11765

    Last Modified: 21 Nov 2024

    A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2020-6583

    Last Modified: 21 Nov 2024

    BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account via the Name field in an Add New Client action.

    Published: 8 Jan 2020
    5.5
    Medium

    CVE-2016-5346

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).

    Published: 8 Jan 2020
    4.7
    Medium

    CVE-2020-0008

    Last Modified: 21 Nov 2024

    In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142558228

    Published: 8 Jan 2020
    5.5
    Medium

    CVE-2020-0007

    Last Modified: 21 Nov 2024

    In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2020-0006

    Last Modified: 21 Nov 2024

    In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-139738828

    Published: 8 Jan 2020
    5.5
    Medium

    CVE-2020-0004

    Last Modified: 21 Nov 2024

    In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120847476

    Published: 8 Jan 2020
    6.7
    Medium

    CVE-2020-0003

    Last Modified: 21 Nov 2024

    In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android ID: A-140195904

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-0002

    Last Modified: 21 Nov 2024

    In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142602711

    Published: 8 Jan 2020
    7.8
    High

    CVE-2020-0001

    Last Modified: 21 Nov 2024

    In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-140055304

    Published: 8 Jan 2020
    5.3
    Medium

    CVE-2016-6585

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack via specially crafted JavaScript.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2020-5511

    Last Modified: 21 Nov 2024

    PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2020-5510

    Last Modified: 11 Nov 2025

    PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.

    Published: 8 Jan 2020
    7.5
    High

    CVE-2020-5183

    Last Modified: 21 Nov 2024

    FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string to the application. This memory corruption bug can possibly be classified as a NULL pointer dereference.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-19495

    Last Modified: 21 Nov 2024

    The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the cable modem to port forward the modem's internal TELNET server, allowing external access to a root shell.

    Published: 8 Jan 2020
    5.5
    Medium

    CVE-2016-6587

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malicious user obtain sensitive information.

    Published: 8 Jan 2020
    3.7
    Low

    CVE-2016-6586

    Last Modified: 21 Nov 2024

    A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially crafted JavaScript to add arbitrary URLs to the URL whitelist.

    Published: 8 Jan 2020
    9.1
    Critical

    CVE-2019-20367

    Last Modified: 21 Nov 2024

    nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

    Published: 8 Jan 2020
    8.8
    High

    CVE-2014-5287

    Last Modified: 21 Nov 2024

    A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2019-20363

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2019-20364

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2019-20365

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2019-20366

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-5082

    Last Modified: 21 Nov 2024

    An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-10777

    Last Modified: 21 Nov 2024

    In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".

    Published: 8 Jan 2020
    5.4
    Medium

    CVE-2016-6588

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.

    Published: 8 Jan 2020