|
219501
|
8.8 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
|
CWE-415
Double Free
|
CVE-2019-20014
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219502
|
6.5 |
MEDIUM
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-20013
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219503
|
6.5 |
MEDIUM
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-20012
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219504
|
8.8 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20011
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219505
|
8.8 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
|
CWE-416
Use After Free
|
CVE-2019-20010
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219506
|
6.5 |
MEDIUM
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-20009
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219507
|
5.4 |
MEDIUM
Network
|
archerysec
|
archery
|
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20008
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219508
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20007
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219509
|
7.5 |
HIGH
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), lea…
|
CWE-416
Use After Free
|
CVE-2019-20006
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219510
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while r…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20005
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|