|
222361
|
8.8 |
HIGH
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
|
CWE-416
Use After Free
|
CVE-2019-20010
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222362
|
6.5 |
MEDIUM
Network
|
gnu opensuse
|
libredwg leap backports_sle
|
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-20009
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222363
|
5.4 |
MEDIUM
Network
|
archerysec
|
archery
|
In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an existing one) will result in stored XSS on the vulnerability-scan scheduling page.
|
CWE-79
Cross-site Scripting
|
CVE-2019-20008
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222364
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, performs zero-length reallocation in ezxml.c, leading to returning a NULL pointer …
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-20007
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222365
|
7.5 |
HIGH
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), lea…
|
CWE-416
Use After Free
|
CVE-2019-20006
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222366
|
6.5 |
MEDIUM
Network
|
ezxml_project
|
ezxml
|
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while r…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-20005
|
2024-11-21 13:37 |
2019-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222367
|
5.9 |
MEDIUM
Network
|
bullguard
|
premium_protection
|
The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-20000
|
2024-11-21 13:37 |
2019-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222368
|
5.3 |
MEDIUM
Network
|
cisco
|
firepower_management_center firepower_threat_defense firepower_services_software_for_asa
|
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could all…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-1982
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222369
|
5.8 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense firepower_management_center firepower_services_software_for_asa
|
A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an…
|
CWE-20
Improper Input Validation
|
CVE-2019-1981
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222370
|
5.3 |
MEDIUM
Network
|
cisco
|
firepower_threat_defense firepower_management_center firepower_services_software_for_asa
|
A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow a…
|
CWE-287
Improper Authentication
|
CVE-2019-1980
|
2024-11-21 13:37 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|