Unknown · CVSS Not scored
An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when viewing the list of file types, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role with the "Administer file types" permission.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and without a PAM configuration suitable for use with setuid account management tools. This combination leads to account management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that can easily be used by unprivileged local users to escalate privileges to root in multiple ways. This issue became much more relevant in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed in the upstream Makefile which is now included in the release version 4.8).
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Published Dec 19, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.
Published Dec 19, 2019 · Updated Aug 5, 2024
Medium · CVSS 5.5
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
Published Dec 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
Published Dec 18, 2019 · Updated Aug 5, 2024
Medium · CVSS 6.8
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return depending on whether an email address is configured for the account name provided. This can be used by an attacker to enumerate accounts by guessing email addresses.
Published Dec 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges.
Published Dec 13, 2019 · Updated Aug 5, 2024
High · CVSS 8.8
An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires having the system extension ext:lowlevel (Backend Module: DB Check) installed, with a valid backend user who has administrator privileges. The other exploitable scenario requires having the system extension ext:sys_action installed, with a valid backend user who has limited privileges.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.
Published Dec 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.
Published Dec 16, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
Published Dec 15, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read primitive.
Published Dec 16, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
Published Dec 12, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.
Published Dec 16, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.
Published Dec 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
Published Dec 12, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file.
Published Dec 13, 2019 · Updated Aug 5, 2024
High · CVSS 8.1
The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.
Published Dec 16, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
samurai 0.7 has a heap-based buffer overflow in canonpath in util.c via a crafted build file.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).
Published Dec 12, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.
Published Dec 16, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.
Published Dec 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.
Published Dec 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.
Published Dec 13, 2019 · Updated Aug 5, 2024