CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-19590

    Last Modified: 21 Nov 2024

    In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at libr/asm/asm.c. This integer overflow will result in a Use-After-Free for the buffer tokens, which can be filled with arbitrary malicious data after the free. This allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted input.

    Published: 5 Dec 2019
    7.5
    High

    CVE-2019-19588

    Last Modified: 21 Nov 2024

    The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a crafted domain string. This is fixed in 0.12.6.

    Published: 5 Dec 2019
    5.7
    Medium

    CVE-2019-20485

    Last Modified: 21 Nov 2024

    qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-19317

    Last Modified: 21 Nov 2024

    lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-19334

    Last Modified: 21 Nov 2024

    In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

    Published: 5 Dec 2019
    5.9
    Medium

    CVE-2019-19794

    Last Modified: 21 Nov 2024

    The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

    Published: 5 Dec 2019
    8.8
    High

    CVE-2019-14889

    Last Modified: 21 Nov 2024

    A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.

    Published: 5 Dec 2019
    5.3
    Medium

    CVE-2019-16770

    Last Modified: 21 Nov 2024

    In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait permanently if the attacker sends requests frequently enough. This vulnerability is patched in Puma 4.3.1 and 3.12.2.

    Published: 5 Dec 2019
    9.8
    Critical

    CVE-2019-19333

    Last Modified: 21 Nov 2024

    In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

    Published: 5 Dec 2019
    6.1
    Medium

    CVE-2019-19587

    Last Modified: 21 Nov 2024

    In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the source view in the Management Console.

    Published: 4 Dec 2019
    7.8
    High

    CVE-2019-19519

    Last Modified: 21 Nov 2024

    In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.

    Published: 4 Dec 2019
    7.8
    High

    CVE-2019-19520

    Last Modified: 21 Nov 2024

    xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-19521

    Last Modified: 21 Nov 2024

    libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

    Published: 4 Dec 2019
    7.8
    High

    CVE-2019-19522

    Last Modified: 21 Nov 2024

    OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2013-2745

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

    Published: 4 Dec 2019
    6.8
    Medium

    CVE-2019-19579

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untrusted guests. Unfortunately, this is not considered a strictly required step for device assignment. The PCI passthrough documentation on the wiki describes alternate ways of preparing devices for assignment, and libvirt uses its own ways as well. Hosts where these "alternate" methods are used will still leave the system in a vulnerable state after the device comes back from a guest. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.

    Published: 4 Dec 2019
    6.5
    Medium

    CVE-2019-11216

    Last Modified: 21 Nov 2024

    BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are allowed.

    Published: 4 Dec 2019
    4.3
    Medium

    CVE-2019-16752

    Last Modified: 21 Nov 2024

    An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact that they are using the product. This also affects Dash Core through 0.14.0.3 and Private Instant Verified Transactions (PIVX) through 3.4.0.

    Published: 4 Dec 2019
    7.5
    High

    CVE-2019-16753

    Last Modified: 21 Nov 2024

    An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is composed of a representation of strings, rather than being composed of their binary representations. This is a weak signature scheme design that would allow the reuse of signatures in some cases (or even the reuse of signatures, intended for one type of message, for another type). This also affects Private Instant Verified Transactions (PIVX) through 3.4.0.

    Published: 4 Dec 2019
    6.1
    Medium

    CVE-2019-19133

    Last Modified: 21 Nov 2024

    The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-19228

    Last Modified: 21 Nov 2024

    Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.

    Published: 4 Dec 2019
    6.5
    Medium

    CVE-2019-19229

    Last Modified: 21 Nov 2024

    admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.

    Published: 4 Dec 2019
    7.8
    High

    CVE-2019-19364

    Last Modified: 21 Nov 2024

    A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and CatalystBrowseSuite.2019.1.exe (version 1.1.0.21) installers run. The vulnerability is in the form of DLL Hijacking. The installers try to load DLLs that don’t exist from its current directory; by doing so, an attacker can quickly escalate its privileges.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-19576

    Last Modified: 21 Nov 2024

    class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

    Published: 4 Dec 2019
    5.4
    Medium

    CVE-2019-18347

    Last Modified: 21 Nov 2024

    A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields that can be set by unprivileged users, making it possible for JavaScript stored in those fields to be executed by another (possibly privileged) user. Affected database fields include Username, Display Name, and Email.

    Published: 4 Dec 2019
    8.8
    High

    CVE-2019-18346

    Last Modified: 21 Nov 2024

    A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, the attacker can send arbitrary requests in the name of the user to the application. If the attacked user is an administrator, the attacker could for example add a new admin user.

    Published: 4 Dec 2019
    7.5
    High

    CVE-2019-17555

    Last Modified: 21 Nov 2024

    The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the header, then it can help to implement a DoS attack.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-17556

    Last Modified: 21 Nov 2024

    Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.

    Published: 4 Dec 2019
    5.5
    Medium

    CVE-2019-17554

    Last Modified: 21 Nov 2024

    The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Request with content type "application/xml", which trigger the deserialization of entities, can be used to trigger XXE attacks.

    Published: 4 Dec 2019
    4.8
    Medium

    CVE-2019-7197

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.

    Published: 4 Dec 2019
    7.8
    High

    CVE-2019-7201

    Last Modified: 21 Nov 2024

    An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with elevated system privileges. QNAP have already fixed this issue in QNAP NetBak Replicator 4.5.12.1108.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2018-0730

    Last Modified: 21 Nov 2024

    This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2018-0729

    Last Modified: 21 Nov 2024

    This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-11940

    Last Modified: 21 Nov 2024

    In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.

    Published: 4 Dec 2019
    7.5
    High

    CVE-2018-0728

    Last Modified: 21 Nov 2024

    This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-11934

    Last Modified: 21 Nov 2024

    Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-11935

    Last Modified: 21 Nov 2024

    Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-11936

    Last Modified: 21 Nov 2024

    Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

    Published: 4 Dec 2019
    9.8
    Critical

    CVE-2019-11930

    Last Modified: 21 Nov 2024

    An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

    Published: 4 Dec 2019
    7.5
    High

    CVE-2019-11937

    Last Modified: 21 Nov 2024

    In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.

    Published: 4 Dec 2019
    7.5
    High

    CVE-2019-11923

    Last Modified: 21 Nov 2024

    In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no maximum length enforced, allowing for resource exhaustion or denial of service.

    Published: 4 Dec 2019
    7.4
    High

    CVE-2019-14899

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in use, allowing the bad actor to inject data into the TCP stream. This provides everything that is needed for an attacker to hijack active connections inside the VPN tunnel.

    Published: 4 Dec 2019
    7.8
    High

    CVE-2019-15638

    Last Modified: 21 Nov 2024

    COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.

    Published: 4 Dec 2019
    7.5
    High

    CVE-2019-18850

    Last Modified: 21 Nov 2024

    TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding to different HTTP methods, also via predictible responses when accessing and interacting with the "SITE_PATH_QUERY".

    Published: 4 Dec 2019
    8.8
    High

    CVE-2019-19687

    Last Modified: 21 Nov 2024

    OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2045

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2047

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2071

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019
    5.5
    Medium

    CVE-2020-21490

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.

    Published: 4 Dec 2019
    —
    Unknown

    CVE-2020-2046

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 4 Dec 2019