CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2019-6686

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, the Traffic Management Microkernel (TMM) might stop responding after the total number of diameter connections and pending messages on a single virtual server has reached 32K.

    Published: 23 Dec 2019
    7.5
    High

    CVE-2019-6681

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a memory leak in Multicast Forwarding Cache (MFC) handling in tmrouted.

    Published: 23 Dec 2019
    3.3
    Low

    CVE-2019-6679

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.0.0-15.0.1, 14.1.0.2-14.1.2.2, 14.0.0.5-14.0.1, 13.1.1.5-13.1.3.1, 12.1.4.1-12.1.5, 11.6.4-11.6.5, and 11.5.9-11.5.10, the access controls implemented by scp.whitelist and scp.blacklist are not properly enforced for paths that are symlinks. This allows authenticated users with SCP access to overwrite certain configuration files that would otherwise be restricted.

    Published: 23 Dec 2019
    7.5
    High

    CVE-2019-6683

    Last Modified: 21 Nov 2024

    On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, BIG-IP virtual servers with Loose Initiation enabled on a FastL4 profile may be subject to excessive flow usage under undisclosed conditions.

    Published: 23 Dec 2019
    5.3
    Medium

    CVE-2019-6678

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, the TMM process may restart when the packet filter feature is enabled.

    Published: 23 Dec 2019
    7.5
    High

    CVE-2019-6682

    Last Modified: 21 Nov 2024

    On versions 15.0.0-15.0.1.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP ASM system may consume excessive resources when processing certain types of HTTP responses from the origin web server. This vulnerability is only known to affect resource-constrained systems in which the security policy is configured with response-side features, such as Data Guard or response-side learning.

    Published: 23 Dec 2019
    7.5
    High

    CVE-2019-6677

    Last Modified: 21 Nov 2024

    On BIG-IP versions 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, under certain conditions when using custom TCP congestion control settings in a TCP profile, TMM stops processing traffic when processed by an iRule.

    Published: 23 Dec 2019
    7.5
    High

    CVE-2019-6676

    Last Modified: 21 Nov 2024

    On versions 15.0.0-15.0.1, 14.0.0-14.1.2.2, and 13.1.0-13.1.3.1, TMM may restart on BIG-IP Virtual Edition (VE) when using virtio direct descriptors and packets 2 KB or larger.

    Published: 23 Dec 2019
    6.5
    Medium

    CVE-2019-19930

    Last Modified: 21 Nov 2024

    In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.

    Published: 23 Dec 2019
    8.8
    High

    CVE-2019-19931

    Last Modified: 21 Nov 2024

    In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.

    Published: 23 Dec 2019
    7.8
    High

    CVE-2019-19929

    Last Modified: 21 Nov 2024

    An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-19952

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

    Published: 23 Dec 2019
    7.5
    High

    CVE-2019-19959

    Last Modified: 21 Nov 2024

    ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

    Published: 23 Dec 2019
    3.8
    Low

    CVE-2020-12829

    Last Modified: 21 Nov 2024

    In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this flaw to crash the QEMU process in sm501_2d_operation() in hw/display/sm501.c on the host, resulting in a denial of service.

    Published: 23 Dec 2019
    9.8
    Critical

    CVE-2019-19948

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

    Published: 23 Dec 2019
    9.1
    Critical

    CVE-2019-19949

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.

    Published: 23 Dec 2019
    8.8
    High

    CVE-2019-19920

    Last Modified: 21 Nov 2024

    sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

    Published: 22 Dec 2019
    5.3
    Medium

    CVE-2019-25025

    Last Modified: 21 Nov 2024

    The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Consequently, remote attackers can leverage timing discrepancies to achieve a correct guess in a relatively short amount of time. This is a related issue to CVE-2019-16782.

    Published: 22 Dec 2019
    3.7
    Low

    CVE-2019-11045

    Last Modified: 17 Aug 2026

    In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.

    Published: 22 Dec 2019
    5.5
    Medium

    CVE-2019-19922

    Last Modified: 21 Nov 2024

    kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)

    Published: 22 Dec 2019
    4.8
    Medium

    CVE-2019-11047

    Last Modified: 21 Nov 2024

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

    Published: 22 Dec 2019
    5.5
    Medium

    CVE-2020-35507

    Last Modified: 21 Nov 2024

    There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.

    Published: 22 Dec 2019
    5.5
    Medium

    CVE-2020-35496

    Last Modified: 21 Nov 2024

    There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

    Published: 22 Dec 2019
    7
    High

    CVE-2019-19921

    Last Modified: 21 Nov 2024

    runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)

    Published: 21 Dec 2019
    5.5
    Medium

    CVE-2020-35493

    Last Modified: 21 Nov 2024

    A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

    Published: 21 Dec 2019
    5.5
    Medium

    CVE-2020-35495

    Last Modified: 21 Nov 2024

    There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.

    Published: 21 Dec 2019
    —
    Unknown

    CVE-2019-16787

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-19905. Reason: This candidate is a duplicate of CVE-2019-19905. Notes: All CVE users should reference CVE-2019-19905 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Dec 2019
    7.3
    High

    CVE-2019-19231

    Last Modified: 21 Nov 2024

    An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3 Agent for Windows that can allow a local attacker to gain escalated privileges.

    Published: 20 Dec 2019
    6.5
    Medium

    CVE-2019-15584

    Last Modified: 21 Nov 2024

    A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validation in markdown fields take down the affected page.

    Published: 20 Dec 2019
    7.8
    High

    CVE-2019-19917

    Last Modified: 21 Nov 2024

    Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

    Published: 20 Dec 2019
    7.8
    High

    CVE-2019-19918

    Last Modified: 21 Nov 2024

    Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

    Published: 20 Dec 2019
    9.8
    Critical

    CVE-2019-19747

    Last Modified: 21 Nov 2024

    NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

    Published: 20 Dec 2019
    6.1
    Medium

    CVE-2019-4744

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172882.

    Published: 20 Dec 2019
    4.3
    Medium

    CVE-2019-4743

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 172880.

    Published: 20 Dec 2019
    6.1
    Medium

    CVE-2019-4742

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 172877.

    Published: 20 Dec 2019
    4.3
    Medium

    CVE-2019-4736

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172706.

    Published: 20 Dec 2019
    5.4
    Medium

    CVE-2019-4555

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166204.

    Published: 20 Dec 2019
    4.3
    Medium

    CVE-2019-4231

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 159356.

    Published: 20 Dec 2019
    8.8
    High

    CVE-2018-1934

    Last Modified: 21 Nov 2024

    IBM Cognos Business Intelligence 10.2.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 153179.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2019-15914

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

    Published: 20 Dec 2019
    9.8
    Critical

    CVE-2019-15913

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2019-15912

    Last Modified: 21 Nov 2024

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.

    Published: 20 Dec 2019
    9.8
    Critical

    CVE-2019-15911

    Last Modified: 21 Nov 2024

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because of insecure key transport in ZigBee communication, attackers can obtain sensitive information, cause the multiple denial of service attacks, take over smart home devices, and tamper with messages.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2019-15910

    Last Modified: 21 Nov 2024

    An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2019-15915

    Last Modified: 21 Nov 2024

    An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover ZigBee network procedure" to perform a denial of service attack.

    Published: 20 Dec 2019
    6.5
    Medium

    CVE-2019-18263

    Last Modified: 21 Nov 2024

    An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped between 26-June-2017 through 07-August 2018), Pulsera (718095) and Endura (718075) with ViewForum option (shipped between 26-June-2017 through 07-August 2018). The router software uses an encryption scheme that is not strong enough for the level of protection required.

    Published: 20 Dec 2019
    10
    Critical

    CVE-2019-17440

    Last Modified: 21 Nov 2024

    Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 versions prior to 9.0.5-h3 on PA-7080 and PA-7050 devices with an LFC installed and configured. This issue does not affect PA-7000 Series deployments using the first-generation SMC and the Log Processing Card (LPC). This issue does not affect any other PA series devices. This issue does not affect devices without an LFC. This issue does not affect PAN-OS 8.1 or prior releases. This issue only affected a very limited number of customers and we undertook individual outreach to help them upgrade. At the time of publication, all identified customers have upgraded SW or content and are not impacted.

    Published: 20 Dec 2019
    6.1
    Medium

    CVE-2019-19916

    Last Modified: 21 Nov 2024

    In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing for cross-site scripting (XSS) and other attacks when the product renders the content as HTML. Remediating this would also need to consider the polyglot case, e.g., a file that is a valid GIF image and also valid JavaScript.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2012-6111

    Last Modified: 21 Nov 2024

    gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

    Published: 20 Dec 2019
    6.1
    Medium

    CVE-2019-19908

    Last Modified: 21 Nov 2024

    phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.

    Published: 20 Dec 2019