|
221891
|
5.4 |
MEDIUM
Network
|
archerysec
|
archery
|
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20008
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221892
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20007
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221893
|
7.5 |
HIGH
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), lea…
|
CWE-416
Use After Free
|
CVE-2019-20006
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221894
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while r…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20005
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221895
|
5.9 |
MEDIUM
Network
|
bullguard
|
premium_protection
|
The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-20000
|
2024-11-21 13:37 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221896
|
5.3 |
MEDIUM
Network
|
cisco
|
firepower_management_center firepower_threat_defense firepower_services_software_for_asa
|
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could all…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-1982
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221897
|
5.8 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense firepower_management_center firepower_services_software_for_asa
|
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an…
|
CWE-20
Improper Input Validation
|
CVE-2019-1981
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221898
|
5.3 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense firepower_management_center firepower_services_software_for_asa
|
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow a…
|
CWE-287
Improper Authentication
|
CVE-2019-1980
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221899
|
5.8 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense firepower_management_center firepower_services_software_for_asa
|
A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an…
|
CWE-20
Improper Input Validation
|
CVE-2019-1978
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221900
|
6.5 |
MEDIUM
Network
|
cisco
|
enterprise_chat_and_email
|
A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insuff…
|
CWE-287
Improper Authentication
|
CVE-2019-1877
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|