CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-20162

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20163

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20164

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_box_del() in isomedia/box_funcs.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20165

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20166

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_isom_dump() in isomedia/box_dump.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20167

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function senc_Parse() in isomedia/box_code_drm.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20168

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function gf_isom_box_dump_ex() in isomedia/box_funcs.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20169

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a use-after-free in the function trak_Read() in isomedia/box_code_base.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20170

    Last Modified: 21 Nov 2024

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.

    Published: 30 Dec 2019
    5.5
    Medium

    CVE-2019-20171

    Last Modified: 4 Mar 2025

    An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c.

    Published: 30 Dec 2019
    9.8
    Critical

    CVE-2019-7478

    Last Modified: 21 Nov 2024

    A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, 8.7, 9.0 and 9.1.

    Published: 30 Dec 2019
    4.3
    Medium

    CVE-2018-20488

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

    Published: 30 Dec 2019
    5.3
    Medium

    CVE-2018-20489

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

    Published: 30 Dec 2019
    5.4
    Medium

    CVE-2018-20491

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

    Published: 30 Dec 2019
    4.3
    Medium

    CVE-2018-20493

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

    Published: 30 Dec 2019
    7.5
    High

    CVE-2018-20494

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

    Published: 30 Dec 2019
    5.3
    Medium

    CVE-2018-20495

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure.

    Published: 30 Dec 2019
    5.4
    Medium

    CVE-2018-20496

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

    Published: 30 Dec 2019
    7.2
    High

    CVE-2018-20499

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

    Published: 30 Dec 2019
    5
    Medium

    CVE-2018-20497

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.

    Published: 30 Dec 2019
    5.3
    Medium

    CVE-2018-20507

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

    Published: 30 Dec 2019
    5.4
    Medium

    CVE-2018-20490

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition 11.2.x through 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows XSS.

    Published: 30 Dec 2019
    4.3
    Medium

    CVE-2018-20498

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

    Published: 30 Dec 2019
    6.3
    Medium

    CVE-2018-20501

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.

    Published: 30 Dec 2019
    7.5
    High

    CVE-2012-5663

    Last Modified: 21 Nov 2024

    The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).

    Published: 30 Dec 2019
    7.5
    High

    CVE-2012-5645

    Last Modified: 21 Nov 2024

    A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.

    Published: 30 Dec 2019
    6.1
    Medium

    CVE-2018-7859

    Last Modified: 21 Nov 2024

    A security vulnerability in D-Link DGS-1510-series switches with firmware 1.20.011, 1.30.007, 1.31.B003 and older that may allow a remote attacker to inject malicious scripts in the device and execute commands via browser that is configuring the unit.

    Published: 30 Dec 2019
    8.1
    High

    CVE-2019-19032

    Last Modified: 21 Nov 2024

    XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload.

    Published: 30 Dec 2019
    6.5
    Medium

    CVE-2019-16790

    Last Modified: 31 Dec 2025

    In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

    Published: 30 Dec 2019
    8.1
    High

    CVE-2019-19031

    Last Modified: 21 Nov 2024

    Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.

    Published: 30 Dec 2019
    9.8
    Critical

    CVE-2019-13445

    Last Modified: 21 Nov 2024

    An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. parseOptions() in tools/rosbag/src/record.cpp has an integer overflow when a crafted split option can be entered on the command line.

    Published: 30 Dec 2019
    8.6
    High

    CVE-2019-13465

    Last Modified: 21 Nov 2024

    An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROS_ASSERT_ENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of service for other components (that depend on the communication-related functions of this package). NOTE: The reporter of this issue now believes it was a false alarm.

    Published: 30 Dec 2019
    7.8
    High

    CVE-2019-19470

    Last Modified: 21 Nov 2024

    Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.

    Published: 30 Dec 2019
    5.3
    Medium

    CVE-2019-19806

    Last Modified: 21 Nov 2024

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

    Published: 30 Dec 2019
    5.3
    Medium

    CVE-2019-19805

    Last Modified: 21 Nov 2024

    _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.

    Published: 30 Dec 2019
    6.1
    Medium

    CVE-2019-19738

    Last Modified: 21 Nov 2024

    log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.

    Published: 30 Dec 2019
    8.8
    High

    CVE-2019-19737

    Last Modified: 21 Nov 2024

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.

    Published: 30 Dec 2019
    6.1
    Medium

    CVE-2019-19736

    Last Modified: 21 Nov 2024

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.

    Published: 30 Dec 2019
    9.1
    Critical

    CVE-2019-19735

    Last Modified: 21 Nov 2024

    class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an attacker to guess the hash and set the password within a few hours by bruteforcing.

    Published: 30 Dec 2019
    8.8
    High

    CVE-2019-19734

    Last Modified: 21 Nov 2024

    _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

    Published: 30 Dec 2019
    6.1
    Medium

    CVE-2019-19733

    Last Modified: 21 Nov 2024

    _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the fileIds parameter on the page, which would allow an attacker to input HTML or execute scripts on the site, aka XSS.

    Published: 30 Dec 2019
    7.2
    High

    CVE-2019-19732

    Last Modified: 21 Nov 2024

    translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

    Published: 30 Dec 2019
    6.1
    Medium

    CVE-2019-20141

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.

    Published: 30 Dec 2019
    7.5
    High

    CVE-2019-19739

    Last Modified: 21 Nov 2024

    MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.

    Published: 30 Dec 2019
    8.8
    High

    CVE-2019-20140

    Last Modified: 24 Apr 2026

    An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.

    Published: 30 Dec 2019
    9.8
    Critical

    CVE-2019-10774

    Last Modified: 21 Nov 2024

    php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 30 Dec 2019
    —
    Unknown

    CVE-2019-4994

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 30 Dec 2019
    —
    Unknown

    CVE-2019-4980

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 30 Dec 2019
    —
    Unknown

    CVE-2019-4993

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 30 Dec 2019
    —
    Unknown

    CVE-2019-4978

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none

    Published: 30 Dec 2019