Vulnerabilities (CVE)

Filtered by CWE-20
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0166 1 Intel 1 Active Management Technology Firmware 2020-01-02 5.0 MEDIUM 7.5 HIGH
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
CVE-2019-0131 1 Intel 1 Active Management Technology Firmware 2020-01-02 4.8 MEDIUM 8.1 HIGH
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.
CVE-2019-11103 1 Intel 1 Converged Security Management Engine Firmware 2020-01-02 4.6 MEDIUM 7.8 HIGH
Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2019-11104 1 Intel 2 Converged Security Management Engine Firmware, Trusted Execution Engine Firmware 2020-01-02 4.6 MEDIUM 7.8 HIGH
Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2012-6111 2 Debian, Gnome 2 Debian Linux, Gnome Keyring 2020-01-02 5.0 MEDIUM 7.5 HIGH
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
CVE-2019-11088 1 Intel 1 Active Management Technology Firmware 2019-12-31 5.8 MEDIUM 8.8 HIGH
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
CVE-2019-8503 1 Apple 5 Icloud, Iphone Os, Itunes and 2 more 2019-12-31 9.3 HIGH 8.8 HIGH
A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious website may be able to execute scripts in the context of another website.
CVE-2019-8549 1 Apple 4 Iphone Os, Mac Os X, Tvos and 1 more 2019-12-30 9.3 HIGH 7.8 HIGH
Multiple input validation issues existed in MIG generated code. These issues were addressed with improved validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to execute arbitrary code with system privileges.
CVE-2019-8516 1 Apple 4 Iphone Os, Mac Os X, Tvos and 1 more 2019-12-30 5.0 MEDIUM 7.5 HIGH
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. Processing a maliciously crafted string may lead to a denial of service.
CVE-2019-5266 1 Huawei 2 P30, P30 Firmware 2019-12-27 5.0 MEDIUM 7.5 HIGH
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful exploit may cause the function will be disabled.
CVE-2016-6302 2 Openssl, Oracle 3 Openssl, Linux, Solaris 2019-12-27 5.0 MEDIUM 7.5 HIGH
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.
CVE-2016-5418 3 Libarchive, Oracle, Redhat 10 Libarchive, Linux, Enterprise Linux Desktop and 7 more 2019-12-27 5.0 MEDIUM 7.5 HIGH
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
CVE-2016-4809 3 Libarchive, Oracle, Redhat 9 Libarchive, Linux, Enterprise Linux Desktop and 6 more 2019-12-27 5.0 MEDIUM 7.5 HIGH
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
CVE-2016-4555 3 Canonical, Oracle, Squid-cache 3 Ubuntu Linux, Linux, Squid 2019-12-27 5.0 MEDIUM 7.5 HIGH
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
CVE-2016-2776 3 Hp, Isc, Oracle 5 Hp-ux, Bind, Linux and 2 more 2019-12-27 7.8 HIGH 7.5 HIGH
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
CVE-2019-8788 1 Apple 3 Ipados, Iphone Os, Mac Os X 2019-12-26 5.0 MEDIUM 7.5 HIGH
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.
CVE-2019-8721 1 Apple 1 Xcode 2019-12-23 9.3 HIGH 8.8 HIGH
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVE-2019-8722 1 Apple 1 Xcode 2019-12-23 9.3 HIGH 8.8 HIGH
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVE-2019-8723 1 Apple 1 Xcode 2019-12-22 9.3 HIGH 8.8 HIGH
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVE-2019-8724 1 Apple 1 Xcode 2019-12-22 9.3 HIGH 8.8 HIGH
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.
CVE-2019-8802 1 Apple 1 Mac Os X 2019-12-21 9.3 HIGH 7.8 HIGH
A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.
CVE-2014-8179 2 Docker, Opensuse 3 Cs Engine, Docker, Opensuse 2019-12-21 5.0 MEDIUM 7.5 HIGH
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.
CVE-2019-8561 1 Apple 1 Mac Os X 2019-12-20 6.8 MEDIUM 7.8 HIGH
A logic issue was addressed with improved validation. This issue is fixed in macOS Mojave 10.14.4. A malicious application may be able to elevate privileges.
CVE-2019-8665 1 Apple 2 Iphone Os, Watchos 2019-12-19 5.0 MEDIUM 7.5 HIGH
A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination.
CVE-2019-8637 1 Apple 3 Iphone Os, Tvos, Watchos 2019-12-19 9.3 HIGH 7.8 HIGH
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to gain root privileges.
CVE-2013-0243 1 Haskell 1 Hs-tls 2019-12-17 5.8 MEDIUM 7.4 HIGH
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
CVE-2019-14243 1 Haproxy 1 Proxyprotocol 2019-12-16 5.0 MEDIUM 7.5 HIGH
headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon crash) via a crafted HAProxy PROXY v2 request with truncated source/destination address data.
CVE-2019-19396 1 Omniosce 1 Omnios 2019-12-16 7.8 HIGH 7.5 HIGH
illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple threads calling sendmsg concurrently over a single socket, because uts/common/inet/ip/ip_attr.c mishandles conn_ixa dereferences.
CVE-2012-2248 2 Debian, Dhclient Project 2 Debian Linux, Dhclient 2019-12-16 9.3 HIGH 8.1 HIGH
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
CVE-2019-15705 1 Fortinet 1 Fortios 2019-12-16 5.0 MEDIUM 7.5 HIGH
An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticated remote attacker to crash the SSL VPN service by sending a crafted POST request.
CVE-2013-4245 2 Debian, Gnome 2 Debian Linux, Orca 2019-12-13 4.4 MEDIUM 7.3 HIGH
Orca has arbitrary code execution due to insecure Python module load
CVE-2019-17555 1 Apache 1 Olingo 2019-12-13 5.0 MEDIUM 7.5 HIGH
The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it to the Thread.sleep() method without any check. If a malicious server returns a huge value in the header, then it can help to implement a DoS attack.
CVE-2013-2103 1 Redhat 1 Openshift 2019-12-13 5.5 MEDIUM 8.1 HIGH
OpenShift cartridge allows remote URL retrieval
CVE-2019-1484 1 Microsoft 8 Windows 10, Windows 7, Windows 8.1 and 5 more 2019-12-13 6.8 MEDIUM 7.8 HIGH
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
CVE-2019-1471 1 Microsoft 3 Windows 10, Windows Server 2016, Windows Server 2019 2019-12-13 6.5 MEDIUM 8.2 HIGH
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
CVE-2019-18247 1 Abb 4 Relion 650, Relion 650 Firmware, Relion 670 and 1 more 2019-12-11 7.8 HIGH 7.5 HIGH
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.
CVE-2012-4576 2 Debian, Freebsd 2 Debian Linux, Freebsd 2019-12-11 7.2 HIGH 7.8 HIGH
FreeBSD: Input Validation Flaw allows local users to gain elevated privileges
CVE-2019-15288 1 Cisco 3 Roomos, Telepresence Codec, Telepresence Collaboration Endpoint 2019-12-10 6.5 MEDIUM 8.8 HIGH
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco RoomOS Software could allow an authenticated, remote attacker to escalate privileges to an unrestricted user of the restricted shell. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by including specific arguments when opening an SSH connection to an affected device. A successful exploit could allow the attacker to gain unrestricted user access to the restricted shell of an affected device.
CVE-2019-5268 1 Huawei 44 Cd10-10, Cd10-10 Firmware, Cd16-10 and 41 more 2019-12-09 4.8 MEDIUM 8.1 HIGH
Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.
CVE-2019-5700 2 Google, Nvidia 2 Android, Shield Experience 2019-12-05 7.2 HIGH 7.8 HIGH
NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
CVE-2011-4310 1 Cmsmadesimple 1 Cms Made Simple 2019-12-04 5.0 MEDIUM 7.5 HIGH
The news module in CMSMS before 1.9.4.3 allows remote attackers to corrupt new articles.
CVE-2012-4524 2 Fedoraproject, Sillycycle 2 Fedora, Xlockmore 2019-12-04 5.0 MEDIUM 7.5 HIGH
xlockmore before 5.43 'dclock' security bypass vulnerability
CVE-2013-7172 1 Slackware 1 Slackware Linux 2019-12-03 7.2 HIGH 7.8 HIGH
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.
CVE-2017-13147 1 Graphicsmagick 1 Graphicsmagick 2019-12-03 6.8 MEDIUM 8.8 HIGH
In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value.
CVE-2019-5856 1 Google 1 Chrome 2019-12-02 6.8 MEDIUM 8.8 HIGH
Insufficient policy enforcement in storage in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
CVE-2016-4579 3 Canonical, Libksba Project, Opensuse 3 Ubuntu Linux, Libksba, Leap 2019-11-29 5.0 MEDIUM 7.5 HIGH
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
CVE-2016-4353 2 Canonical, Libksba Project 2 Ubuntu Linux, Libksba 2019-11-29 5.0 MEDIUM 7.5 HIGH
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
CVE-2019-13692 1 Google 1 Chrome 2019-11-27 6.8 MEDIUM 8.8 HIGH
Insufficient policy enforcement in reader mode in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVE-2012-2350 2 Debian, Pam Shield Project 2 Debian Linux, Pam Shield 2019-11-25 5.0 MEDIUM 7.5 HIGH
pam_shield before 0.9.4: Default configuration does not perform protective action
CVE-2015-2156 3 Lightbend, Netty, Playframework 3 Play Framework, Netty, Play Framework 2019-11-25 4.3 MEDIUM 7.5 HIGH
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.