Unknown · CVSS Not scored
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP credentials encoded in a reversible format. Sessions are stored in /sessions/sess_<sessionid>.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82. This will cause a memory leak and denial of service.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
com.proxyman.NSProxy.HelperTool in Privileged Helper Tool in Proxyman for macOS 1.11.0 and earlier allows an attacker to change the System Proxy and redirect all traffic to an attacker-controlled computer, enabling MITM attacks.
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory leak was discovered in Mat_VarCalloc in mat.c in matio 1.5.17 because SafeMulDims does not consider the rank==0 case.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.
Published Dec 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" feature.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets.
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
Published Dec 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '\0' character (where the processing of a string was finished).
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack consumption in readOHDRHeaderMessageDatatype in dataobject.c and directblockRead in fractalhead.c. NOTE: a download of v0.9 after 2019-12-06 should fully remediate this issue.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
Published Dec 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation.
Published Dec 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
Published Dec 27, 2019 · Updated Aug 5, 2024