|
222061
|
5.9 |
MEDIUM
Network
|
postfix-mta-sts-resolver_project
|
postfix-mta-sts-resolver
|
In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, rendering downgrade of effective STS policy.
|
NVD-CWE-Other
|
CVE-2019-16791
|
2024-11-21 13:31 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222062
|
6.1 |
MEDIUM
Network
|
solarwinds
|
orion_platform
|
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and esca…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17127
|
2024-11-21 13:31 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222063
|
6.1 |
MEDIUM
Network
|
solarwinds
|
orion_platform
|
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the An…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17125
|
2024-11-21 13:31 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222064
|
7.8 |
HIGH
Local
|
pyinstaller
|
pyinstaller
|
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a p…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-16784
|
2024-11-21 13:31 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222065
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox ubuntu_linux
|
Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17025
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222066
|
6.5 |
MEDIUM
Network
|
mozilla canonical debian
|
firefox ubuntu_linux debian_linux
|
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state,…
|
CWE-287
Improper Authentication
|
CVE-2019-17023
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222067
|
5.3 |
MEDIUM
Network
|
mozilla opensuse
|
firefox firefox_esr leap
|
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windo…
|
CWE-362
Race Condition
|
CVE-2019-17021
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222068
|
6.5 |
MEDIUM
Network
|
mozilla canonical
|
firefox ubuntu_linux
|
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL …
|
CWE-611
XXE
|
CVE-2019-17020
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222069
|
8.8 |
HIGH
Network
|
mozilla canonical debian redhat opensuse
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux enterprise_linux_eus enterprise…
|
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-17024
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222070
|
6.1 |
MEDIUM
Network
|
mozilla canonical debian redhat
|
firefox firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server…
|
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17022
|
2024-11-21 13:31 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|