|
221721
|
8.8 |
HIGH
Network
|
cesnet
|
libyang
|
A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang fil…
|
CWE-415
Double Free
|
CVE-2019-20394
|
2024-11-21 13:38 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221722
|
8.8 |
HIGH
Network
|
cesnet
|
libyang
|
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to …
|
CWE-415
Double Free
|
CVE-2019-20393
|
2024-11-21 13:38 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221723
|
6.5 |
MEDIUM
Network
|
cesnet
|
libyang
|
An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not def…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-20392
|
2024-11-21 13:38 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221724
|
6.5 |
MEDIUM
Network
|
cesnet
|
libyang
|
An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-feature statement is used inside a bit. Applications that use libyang to parse un…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-20391
|
2024-11-21 13:38 |
2020-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221725
|
7.5 |
HIGH
Network
|
opensuse debian
|
libsolv debian_linux
|
repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20387
|
2024-11-21 13:38 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221726
|
7.5 |
HIGH
Network
|
xmlsoft debian netapp oracle opensuse fedoraproject
|
libxml2 debian_linux cloud_backup steelstore_cloud_integrated_storage ontap_select_deploy_administration_utility clustered_data_ontap smi-s_provider snapdrive plug-in_for_syma…
|
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-20388
|
2024-11-21 13:38 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221727
|
2.4 |
LOW
Physics
|
systemd_project canonical fedoraproject opensuse netapp
|
systemd ubuntu_linux fedora leap cloud_backup steelstore_cloud_integrated_storage active_iq_unified_manager
|
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-20386
|
2024-11-21 13:38 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221728
|
8.8 |
HIGH
Network
|
logaritmo
|
aware_callmanager
|
The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type. The PHP code can then be executed by visiti…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-20385
|
2024-11-21 13:38 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221729
|
5.5 |
MEDIUM
Local
|
gentoo
|
portage
|
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is w…
|
CWE-362
Race Condition
|
CVE-2019-20384
|
2024-11-21 13:38 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221730
|
6.1 |
MEDIUM
Network
|
testlink
|
testlink
|
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20381
|
2024-11-21 13:38 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|