|
222281
|
6.5 |
MEDIUM
Network
|
inspircd debian
|
inspircd debian_linux
|
An issue was discovered in InspIRCd 2 before 2.0.28 and 3 before 3.3.0. The mysql module contains a NULL pointer dereference when built against mariadb-connector-c 3.0.5 or newer. When combined with …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20917
|
2024-11-21 13:39 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222282
|
7.5 |
HIGH
Network
|
pypa opensuse debian oracle
|
pip leap debian_linux communications_cloud_native_core_policy communications_cloud_native_core_network_function_cloud_native_environment
|
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwr…
|
CWE-22
Path Traversal
|
CVE-2019-20916
|
2024-11-21 13:39 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222283
|
8.1 |
HIGH
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20915
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222284
|
9.8 |
CRITICAL
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20914
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222285
|
8.1 |
HIGH
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20913
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222286
|
8.8 |
HIGH
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20912
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222287
|
6.5 |
MEDIUM
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-20911
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222288
|
8.1 |
HIGH
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20910
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222289
|
7.5 |
HIGH
Network
|
gnu
|
libredwg
|
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20909
|
2024-11-21 13:39 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222290
|
6.7 |
MEDIUM
Local
|
linux opensuse canonical
|
linux_kernel leap ubuntu_linux
|
An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for the efivar_ssdt ACPI variable could be used by attackers to bypass lockdown or s…
|
NVD-CWE-noinfo
|
CVE-2019-20908
|
2024-11-21 13:39 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|