Unknown · CVSS Not scored
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.
Published Dec 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.
Published Dec 26, 2019 · Updated Aug 5, 2024
High · CVSS 8.8
A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. There was CSRF with resultant XSS.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A CSRF issue was discovered on Intelbras IWR 3000N 1.8.7 devices, leading to complete control of the router, as demonstrated by v1/system/user.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength.
Published Dec 24, 2019 · Updated Aug 5, 2024
Medium · CVSS 5.8
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.
Published Dec 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.
Published Dec 26, 2019 · Updated Aug 5, 2024
Medium · CVSS 4.3
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to send_test_email.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
Published Dec 25, 2019 · Updated Aug 5, 2024
Medium · CVSS 4.3
In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability, FVM Debug Mode needs to be enabled and an admin-ajax request needs to call the fastvelocity_min_files action.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized content type name, then have an editor execute scripting when creating content, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role with the "Administer content types" permission.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer (in some compilers). After this, the function ezxml_parse_str does not check whether the s variable is not NULL in ezxml.c, leading to a NULL pointer dereference and crash (segmentation fault).
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault.
Published Dec 26, 2019 · Updated Aug 5, 2024
Medium · CVSS 6.5
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
Published Dec 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
Published Dec 24, 2019 · Updated Aug 5, 2024
Medium · CVSS 6.3
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the multipart/x-mixed-replace MIME type. This could result in script running where CSP should have blocked it, allowing for cross-site scripting (XSS) and other attacks when the product renders the content as HTML. Remediating this would also need to consider the polyglot case, e.g., a file that is a valid GIF image and also valid JavaScript.
Published Dec 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number of stray requests. An attack does not affect the stability of the kernel; it only causes mismanagement of application execution.)
Published Dec 22, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
Published Dec 22, 2019 · Updated Aug 5, 2024
Medium · CVSS 5.4
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
Published Dec 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SQLite 3.30.1 mishandles certain parser-tree rewriting, related to expr.c, vdbeaux.c, and window.c. This is caused by incorrect sqlite3WindowRewrite() error handling.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.
Published Dec 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.
Published Dec 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
Published Dec 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos.
Published Dec 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
Published Dec 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
Published Dec 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c. This is related to the vmwgfx or ttm module.
Published Dec 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would be required to have the permission to create custom blocks, which is typically an administrative task.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
Published Dec 19, 2019 · Updated Aug 5, 2024
Critical · CVSS 9
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a loss of site availability, malicious redirects, and user infections. This could also be exploited via CSRF.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow.
Published Dec 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
Published Dec 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
Published Dec 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client's IP address). This can occur within a talk page topical header that is viewed within a mobile (MobileFrontend) context.
Published Dec 19, 2019 · Updated Aug 5, 2024