LiveActive security incident?Get immediate response
CVE archive

November 2019

Browse CVE records published in November 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1281 matching CVEs · Page 4 of 26.

Unknown · CVSS Not scored

CVE-2019-19451: When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the...

When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.

Published Nov 29, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19329: In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in r...

In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.

Published Nov 27, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19275: typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read.

typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)

Published Nov 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19203: An issue was discovered in Oniguruma 6.x before 6.9.4_rc2.

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.

Published Nov 21, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19269: An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.

Published Nov 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19270: An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b.

An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.

Published Nov 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19274: typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read.

typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)

Published Nov 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19272: An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6.

An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.

Published Nov 26, 2019 · Updated Aug 5, 2024