LiveActive security incident?Get immediate response
CVE archive

December 2019

Browse CVE records published in December 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1489 matching CVEs · Page 8 of 30.

Unknown · CVSS Not scored

CVE-2019-19682: nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\...

nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id]. NOTE: the vendor reportedly considers this a "feature" because the affected components are an HTML content editor.

Published Dec 9, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19783: An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8.

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c.

Published Dec 16, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19747: NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty pass...

NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which allows an attacker with access to the Neuvector portal to authenticate as any valid LDAP user by providing a valid username and an empty password (provided that the active directory server has not been configured to reject empty passwords).

Published Dec 20, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19770: In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/...

In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file). NOTE: Linux kernel developers dispute this issue as not being an issue with debugfs, instead this is an issue with misuse of debugfs within blktrace

Published Dec 12, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19726: OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid pr...

OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing chpass or passwd (which are setuid root), _dl_setup_env in ld.so tries to strip LD_LIBRARY_PATH from the environment, but fails when it cannot allocate memory. Thus, the attacker is able to execute their own library code as root.

Published Dec 12, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19729: An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js.

An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the user-input, because bson-objectid will return early if it detects _bsontype==ObjectID in the user-input object. As a result, objects in arbitrary forms can bypass formatting if they have a valid bsontype.

Published Dec 11, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19732: translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 d...

translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.

Published Dec 30, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19731: Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal.

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

Published Dec 16, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19681: Pandora FMS 7.x suffers from remote code execution vulnerability.

Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root/Administrator. NOTE: The product vendor states that the vulnerability as it is described is not in fact an actual vulnerability. They state that to be able to create alert commands, you need to have admin rights. They also state that the extended ACL system can disable access to specific sections of the configuration, such as defining new alert commands

Published Dec 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19675: In Ivanti Workspace Control before 10.3.180.0.

In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that should be blocked.

Published Dec 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19620: In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry...

In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a file. This is limited in scope to the collection of process-execution telemetry, for executions against specific files where the SYSTEM user was denied access to the source file.

Published Dec 6, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19693: The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local...

The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Published Dec 20, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19687: OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

Published Dec 9, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19702: The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack w...

The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the /dev/random file within XML documents that are emailed to the address in the rua field of the DMARC records of a domain.

Published Dec 10, 2019 · Updated Aug 5, 2024