|
219351
|
7.5 |
HIGH
Network
|
prboom-plus_project
|
prboom-plus
|
An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for handling received UDP packets, as demonstrated by I_SendPacket or I_SendPacket…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20797
|
2024-11-21 13:39 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219352
|
4.4 |
MEDIUM
Local
|
iproute2_project canonical
|
iproute2 ubuntu_linux
|
iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a co…
|
CWE-416
Use After Free
|
CVE-2019-20795
|
2024-11-21 13:39 |
2020-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219353
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-20794
|
2024-11-21 13:39 |
2020-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219354
|
5.4 |
MEDIUM
Network
|
servicenow
|
it_service_management
|
ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_item_guid and sys_id parameters in an Incident Req…
|
CWE-79
Cross-site Scripting
|
CVE-2019-20768
|
2024-11-21 13:39 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219355
|
7.8 |
HIGH
Local
|
lg
|
bridge
|
An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2019-20781
|
2024-11-21 13:39 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219356
|
6.8 |
MEDIUM
Physics
|
opensc_project
|
opensc
|
OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey.c lacks a uniqueness check.
|
CWE-415
Double Free
|
CVE-2019-20792
|
2024-11-21 13:39 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219357
|
9.8 |
CRITICAL
Network
|
google
|
openthread
|
OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc.
|
CWE-787
Out-of-bounds Write
|
CVE-2019-20791
|
2024-11-21 13:39 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219358
|
9.8 |
CRITICAL
Network
|
trusteddomain pypolicyd-spf_project fedoraproject
|
opendmarc pypolicyd-spf fedora
|
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM fi…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2019-20790
|
2024-11-21 13:39 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219359
|
4.8 |
MEDIUM
Network
|
croogo
|
croogo
|
Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20789
|
2024-11-21 13:39 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219360
|
9.8 |
CRITICAL
Network
|
libvnc_project canonical debian siemens
|
libvncserver ubuntu_linux debian_linux simatic_itc1500_firmware simatic_itc1500_pro_firmware simatic_itc1900_firmware simatic_itc1900_pro_firmware simatic_itc2200_firmware sim…
|
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-20788
|
2024-11-21 13:39 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|