CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2012-5693

    Last Modified: 21 Nov 2024

    Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or (4) SEAttack.pl in frameworkgui/; the phNo2Attack parameter to (5) CSAttack.pl or (6) SEAttack.pl in frameworkgui/; the (7) platformDD2 parameter to frameworkgui/SEAttack.pl; the (8) agentURLPath or (9) agentControlKey parameter to frameworkgui/attach2agents.pl; or the (10) controlKey parameter to frameworkgui/attachMobileModem.pl. NOTE: The hostingPath parameter to CSAttack.pl and SEAttack.pl vectors and the appURLPath parameter to attachMobileModem.pl vector are covered by CVE-2012-5878.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2019-11994

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. An API is used to execute a command manifest file during upgrade does not correctly prevent directory traversal and so can be used to execute manifest files in arbitrary locations on the node. The API does not require user authentication and is accessible over the management network, resulting in the potential for unauthenticated remote execution of manifest files. For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061901&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

    Published: 3 Jan 2020
    7.5
    High

    CVE-2019-11993

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell nodes. Two now deprecated APIs run as root, accept a file name path, and can be used to create or delete arbitrary files on the nodes. These APIs do not require user authentication and are accessible over the management network, resulting in remote availability and integrity vulnerabilities For all customers running HPE OmniStack version 3.7.9 and earlier. HPE recommends upgrading the OmniStack software to version 3.7.10 or later, which contains a permanent resolution. Customers and partners who can upgrade to 3.7.10 should upgrade at the earliest convenience. For all customers and partners unable to upgrade their environments to the recommended version 3.7.10, HPE has created a Temporary Workaround https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=mmr_sf-EN_US000061675&withFrame for you to implement. All customer should upgrade to the recommended 3.7.10 or later version at the earliest convenience.

    Published: 3 Jan 2020
    4.9
    Medium

    CVE-2019-19310

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19309

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19263

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19262

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.

    Published: 3 Jan 2020
    8.8
    High

    CVE-2019-19261

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

    Published: 3 Jan 2020
    5.4
    Medium

    CVE-2019-19260

    Last Modified: 21 Nov 2024

    GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19259

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).

    Published: 3 Jan 2020
    5.3
    Medium

    CVE-2019-19258

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.

    Published: 3 Jan 2020
    5.3
    Medium

    CVE-2019-19257

    Last Modified: 21 Nov 2024

    GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).

    Published: 3 Jan 2020
    5.3
    Medium

    CVE-2019-19256

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19255

    Last Modified: 21 Nov 2024

    GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.

    Published: 3 Jan 2020
    6.1
    Medium

    CVE-2012-4451

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.

    Published: 3 Jan 2020
    5.3
    Medium

    CVE-2019-19254

    Last Modified: 21 Nov 2024

    GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2019-19088

    Last Modified: 21 Nov 2024

    Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19087

    Last Modified: 21 Nov 2024

    Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2019-19086

    Last Modified: 21 Nov 2024

    Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).

    Published: 3 Jan 2020
    5.4
    Medium

    CVE-2019-19311

    Last Modified: 21 Nov 2024

    GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

    Published: 3 Jan 2020
    5.5
    Medium

    CVE-2020-1785

    Last Modified: 21 Nov 2024

    Mate 10 Pro;Honor V10;Honor 10;Nova 4 smartphones have a denial of service vulnerability. The system does not properly check the status of certain module during certain operations, an attacker should trick the user into installing a malicious application, successful exploit could cause reboot of the smartphone.

    Published: 3 Jan 2020
    7.5
    High

    CVE-2019-5304

    Last Modified: 21 Nov 2024

    Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.

    Published: 3 Jan 2020
    8.2
    High

    CVE-2020-1871

    Last Modified: 21 Nov 2024

    USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; V500R005C00SPC200 have an improper credentials management vulnerability. The software does not properly manage certain credentials. Successful exploit could cause information disclosure or damage, and impact the confidentiality or integrity.

    Published: 3 Jan 2020
    6.5
    Medium

    CVE-2019-19441

    Last Modified: 21 Nov 2024

    HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An attacker could send specific command in the local area network (LAN) to exploit this vulnerability. Successful exploitation may cause information leak.

    Published: 3 Jan 2020
    7.5
    High

    CVE-2019-19911

    Last Modified: 21 Nov 2024

    There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.

    Published: 3 Jan 2020
    4.3
    Medium

    CVE-2020-11609

    Last Modified: 21 Nov 2024

    An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid descriptors, as demonstrated by a NULL pointer dereference, aka CID-485b06aadb93.

    Published: 3 Jan 2020
    7.1
    High

    CVE-2020-11668

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

    Published: 3 Jan 2020
    5.5
    Medium

    CVE-2020-12769

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.

    Published: 3 Jan 2020
    8.8
    High

    CVE-2020-5310

    Last Modified: 21 Nov 2024

    libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2020-5311

    Last Modified: 21 Nov 2024

    libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

    Published: 3 Jan 2020
    9.8
    Critical

    CVE-2020-5312

    Last Modified: 21 Nov 2024

    libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

    Published: 3 Jan 2020
    7.1
    High

    CVE-2020-5313

    Last Modified: 21 Nov 2024

    libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.

    Published: 3 Jan 2020
    8.8
    High

    CVE-2020-5395

    Last Modified: 21 Nov 2024

    FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

    Published: 3 Jan 2020
    8.8
    High

    CVE-2020-5496

    Last Modified: 21 Nov 2024

    FontForge 20190801 has a heap-based buffer overflow in the Type2NotDefSplines() function in splinesave.c.

    Published: 3 Jan 2020
    8.1
    High

    CVE-2019-20329

    Last Modified: 21 Nov 2024

    OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.

    Published: 2 Jan 2020
    5.9
    Medium

    CVE-2014-6275

    Last Modified: 21 Nov 2024

    FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk private data in FusionForge.

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20316

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20305

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20306

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20307

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20308

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20309

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20310

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20311

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20312

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20313

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20314

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20315

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20317

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020
    —
    Unknown

    CVE-2019-20318

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during the year 2019. Notes: none

    Published: 2 Jan 2020