Unknown · CVSS Not scored
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
Published Nov 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to device hardware to obtain system information.
Published Nov 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to device hardware to obtain system information.
Published Nov 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
Published Nov 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to device hardware to obtain system information.
Published Nov 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to device hardware to obtain cellular modem information.
Published Nov 15, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
Published Nov 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Anhui Huami Mi Fit application before 4.0.11 for Android has an Unencrypted Update Check.
Published Nov 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Free Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers a malformed SEH, as demonstrated by a 0012ECB4 FreePhot.00425642 42200008 corrupt entry.
Published Nov 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The CBC Gem application before 9.24.1 for Android and before 9.26.0 for iOS has Unencrypted Analytics.
Published Nov 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the fax_uuid parameter.
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the dialplan_uuid parameter.
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id and/or voicemail_id parameter.
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.
Published Nov 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.
Published Nov 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.
Published Nov 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.
Published Nov 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the app_uuid parameter.
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.)
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attackers to inject arbitrary web script or HTML via the c parameter.
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
Published Nov 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing a TTF font file that lacks a name section (due to a g_strconcat call that returns NULL).
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection in tooltips for entities. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are displayed directly, arbitrary JavaScript execution can occur, aka XSS. This was addressed by introducing MathJax as a new mathematics rendering engine. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when reporting the number of results and number of milliseconds. NOTE: this GUI code is no longer bundled with the Wikibase Wikidata Query Service snapshots, such as 0.3.6-SNAPSHOT.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
Published Nov 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause an out-of-bounds write, by sending a crafted MQTT protocol packet.
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
Published Nov 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
Published Nov 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c, as demonstrated by unregister_snap_client, aka CID-9804501fa122.
Published Nov 22, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.
Published Nov 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Published Nov 21, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
Published Nov 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.
Published Nov 21, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
Published Nov 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response.
Published Nov 22, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable initialized to NULL) leads to a crash when validating the certificate of a client connecting to the server in a TLS client/server mutual-authentication setup.
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
Published Nov 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
Published Nov 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.
Published Nov 25, 2019 · Updated Aug 5, 2024