CVE-2014-0241
|
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
Published:
December 13, 2019; 08:15:11 AM -05:00
|
(not available)
|
CVE-2014-0212
|
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
Published:
December 13, 2019; 08:15:10 AM -05:00
|
(not available)
|
CVE-2014-0197
|
CFME: CSRF protection vulnerability via permissive check of the referrer header
Published:
December 13, 2019; 08:15:10 AM -05:00
|
(not available)
|
CVE-2014-0175
|
mcollective has a default password set at install
Published:
December 13, 2019; 08:15:10 AM -05:00
|
(not available)
|
CVE-2019-19782
|
The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
Published:
December 13, 2019; 01:15:11 AM -05:00
|
(not available)
|
CVE-2019-19778
|
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
Published:
December 12, 2019; 09:15:10 PM -05:00
|
(not available)
|
CVE-2019-19777
|
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Published:
December 12, 2019; 09:15:10 PM -05:00
|
(not available)
|
CVE-2019-16777
|
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Published:
December 12, 2019; 08:15:11 PM -05:00
|
(not available)
|
CVE-2019-16776
|
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user?s system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Published:
December 12, 2019; 08:15:10 PM -05:00
|
(not available)
|
CVE-2019-16775
|
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user?s system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Published:
December 12, 2019; 08:15:10 PM -05:00
|
(not available)
|
CVE-2019-16774
|
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
Published:
December 12, 2019; 06:15:12 PM -05:00
|
(not available)
|
CVE-2019-12420
|
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
Published:
December 12, 2019; 06:15:12 PM -05:00
|
(not available)
|
CVE-2018-11805
|
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places.
Published:
December 12, 2019; 06:15:11 PM -05:00
|
(not available)
|
CVE-2019-5144
|
A freed memory access vulnerability exists in the SVG Marker Element feature of Apple Safari's WebKit version 13.0.2. A specially crafted HTML web page can cause a use after free, resulting in memory corruption and possibly arbitrary code execution. To trigger this vulnerability, a specifically crafted HTML web page needs to be opened in the browser.
Published:
December 12, 2019; 05:15:11 PM -05:00
|
(not available)
|
CVE-2019-5062
|
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.
Published:
December 12, 2019; 05:15:11 PM -05:00
|
(not available)
|
CVE-2019-5061
|
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.
Published:
December 12, 2019; 05:15:11 PM -05:00
|
(not available)
|
CVE-2019-3951
|
Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.
Published:
December 12, 2019; 04:15:12 PM -05:00
|
(not available)
|
CVE-2019-19771
|
The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.
Published:
December 12, 2019; 03:15:17 PM -05:00
|
(not available)
|
CVE-2019-19770
|
In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (which is used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file).
Published:
December 12, 2019; 03:15:17 PM -05:00
|
(not available)
|
CVE-2019-19769
|
In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).
Published:
December 12, 2019; 03:15:17 PM -05:00
|
(not available)
|