LiveActive security incident?Get immediate response
CVE archive

December 2019

Browse CVE records published in December 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1489 matching CVEs · Page 7 of 30.

Unknown · CVSS Not scored

CVE-2019-19903: An issue was discovered in Backdrop CMS 1.14.x before 1.14.2.

An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when viewing the list of file types, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role with the "Administer file types" permission.

Published Dec 19, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19902: An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2.

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.

Published Dec 19, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19882: shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local us...

shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid, and without a PAM configuration suitable for use with setuid account management tools. This combination leads to account management tools (groupadd, groupdel, groupmod, useradd, userdel, usermod) that can easily be used by unprivileged local users to escalate privileges to root in multiple ways. This issue became much more relevant in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod calls to suidusbins were fixed in the upstream Makefile which is now included in the release version 4.8).

Published Dec 18, 2019 · Updated Aug 5, 2024

Medium · CVSS 5.5

CVE-2019-19850: An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2.

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-submitted content is mishandled, the class QueryGenerator is vulnerable to SQL injection. Exploitation requires having the system extension ext:lowlevel installed, and a valid backend user who has administrator privileges.

Published Dec 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19844: Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover.

Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters) would allow an attacker to be sent a password reset token for the matched user account. (One mitigation in the new releases is to send password reset tokens only to the registered user email address.)

Published Dec 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19807: In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refacto...

In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.

Published Dec 15, 2019 · Updated Aug 5, 2024

Medium · CVSS 6.8

CVE-2019-19848: An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2.

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)

Published Dec 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19846: In Joomla!

In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL injection vectors.

Published Dec 18, 2019 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2019-19849: An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2.

An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires having the system extension ext:lowlevel (Backend Module: DB Check) installed, with a valid backend user who has administrator privileges. The other exploitable scenario requires having the system extension ext:sys_action installed, with a valid backend user who has limited privileges.

Published Dec 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19845: In Joomla!

In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure.

Published Dec 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19813: In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then...

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.

Published Dec 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19832: Xerox AltaLink C8035 printers allow CSRF.

Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)

Published Dec 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19790: Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an im...

Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions were affected. To avoid this vulnerability, you must remove RadChart's HTTP handler from a web.config (its type is Telerik.Web.UI.ChartHttpHandler).

Published Dec 13, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19788: Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack.

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.

Published Dec 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19774: An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110.

An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.

Published Dec 13, 2019 · Updated Aug 5, 2024