| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7940 | — | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking. | |
| CVE-2020-7939 | — | Hig | 0.57 | 8.8 | 0.01 | Jan 23, 2020 | SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.) | |
| CVE-2020-7938 | — | Hig | 0.00 | 8.8 | 0.01 | Jan 23, 2020 | plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level. | |
| CVE-2019-19898 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely. | ||
| CVE-2019-19895 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of… | ||
| CVE-2019-19893 | Hig | 0.49 | 7.5 | 0.03 | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM. | ||
| CVE-2015-5333 | Hig | 0.49 | 7.5 | 0.02 | Jan 23, 2020 | Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates. | ||
| CVE-2013-1593 | Hig | 0.49 | 7.5 | 0.02 | Jan 23, 2020 | A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN. | ||
| CVE-2012-5626 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs… | ||
| CVE-2020-7220 | — | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2. | |
| CVE-2019-16514 | Hig | 0.47 | 7.2 | 0.04 | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server. | ||
| CVE-2019-16513 | Hig | 0.57 | 8.8 | 0.01 | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests. | ||
| CVE-2019-15712 | Hig | 0.47 | 7.2 | 0.01 | Jan 23, 2020 | An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for. | ||
| CVE-2012-6083 | Hig | 0.53 | 7.5 | 0.12 | Jan 23, 2020 | Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet. | ||
| CVE-2019-14888 | Hig | 0.49 | 7.5 | 0.02 | Jan 23, 2020 | A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL. | ||
| CVE-2019-3691 | Hig | 0.50 | 7.7 | 0.01 | Jan 23, 2020 | A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to… | ||
| CVE-2007-6758 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0. | ||
| CVE-2020-7931 | Hig | 0.58 | 8.8 | 0.05 | Jan 23, 2020 | In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the… | ||
| CVE-2019-17202 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2020 | FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. If a user does not have direct access to the elevation feature through group policies, they are prompted to enter a… | ||
| CVE-2019-17201 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2020 | FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. When a user requests elevation using the AdminByRequest.exe interface, the interface communicates with the underlying… | ||
| CVE-2013-6773 | Hig | 0.51 | 7.8 | 0.00 | Jan 23, 2020 | Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges | ||
| CVE-2013-6358 | Hig | 0.57 | 8.8 | 0.04 | Jan 23, 2020 | PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory. | ||
| CVE-2012-5698 | Hig | 0.60 | 8.8 | 0.02 | Jan 23, 2020 | BabyGekko before 1.2.4 has SQL injection. | ||
| CVE-2012-4981 | Hig | 0.57 | 8.8 | 0.03 | Jan 23, 2020 | Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability | ||
| CVE-2008-7314 | Hig | 0.49 | 7.5 | 0.01 | Jan 23, 2020 | mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname. | ||
| CVE-2019-18898 | Hig | 0.50 | 7.7 | 0.00 | Jan 23, 2020 | UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions… | ||
| CVE-2019-19835 | Hig | 0.49 | 7.5 | 0.02 | Jan 23, 2020 | SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI. | ||
| CVE-2019-20397 | Hig | 0.50 | 8.8 | 0.02 | Jan 22, 2020 | A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution. | ||
| CVE-2019-20394 | Hig | 0.50 | 8.8 | 0.03 | Jan 22, 2020 | A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code… | ||
| CVE-2019-20393 | Hig | 0.50 | 8.8 | 0.03 | Jan 22, 2020 | A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution. | ||
| CVE-2019-19834 | Hig | 0.47 | 7.2 | 0.02 | Jan 22, 2020 | Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter. | ||
| CVE-2019-16792 | — | Hig | 0.39 | 7.1 | 0.02 | Jan 22, 2020 | Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Content-Length to 0 internally.… | |
| CVE-2016-4761 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS | ||
| CVE-2011-3613 | Hig | 0.49 | 7.5 | 0.02 | Jan 22, 2020 | An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. | ||
| CVE-2011-3612 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12. | ||
| CVE-2011-3611 | Hig | 0.47 | 7.2 | 0.03 | Jan 22, 2020 | A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12. | ||
| CVE-2011-3582 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions. | ||
| CVE-2019-6858 | Hig | 0.51 | 7.8 | 0.00 | Jan 22, 2020 | A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL. | ||
| CVE-2018-16270 | Hig | 0.49 | 7.5 | 0.01 | Jan 22, 2020 | Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path. | ||
| CVE-2018-16269 | Hig | 0.49 | 7.5 | 0.01 | Jan 22, 2020 | The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build… | ||
| CVE-2018-16267 | Hig | 0.53 | 8.1 | 0.01 | Jan 22, 2020 | The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This… | ||
| CVE-2018-16266 | Hig | 0.53 | 8.1 | 0.01 | Jan 22, 2020 | The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. | ||
| CVE-2018-16263 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2. | ||
| CVE-2018-16262 | Hig | 0.57 | 8.8 | 0.01 | Jan 22, 2020 | The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper D-Bus security policy configurations. Such actions include installing, decrypting, and killing other packages. This affects Tizen before 5.0 M1, and… | ||
| CVE-2020-7595 | — | Hig | 0.49 | 7.5 | 0.08 | Jan 21, 2020 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | |
| CVE-2019-20388 | Hig | 0.49 | 7.5 | 0.04 | Jan 21, 2020 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. | ||
| CVE-2019-20387 | Hig | 0.42 | 7.5 | 0.02 | Jan 21, 2020 | repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema. | ||
| CVE-2019-19414 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2020 | There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system… | ||
| CVE-2019-19413 | Hig | 0.49 | 7.5 | 0.01 | Jan 21, 2020 | There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system… | ||
| CVE-2020-7594 | Hig | 0.47 | 7.2 | 0.02 | Jan 21, 2020 | MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function. |
- risk 0.49cvss 7.5epss 0.01
Missing password strength checks on some forms in Plone 4.3 through 5.2.0 allow users to set weak passwords, leading to easier cracking.
- risk 0.57cvss 8.8epss 0.01
SQL Injection in DTML or in connection objects in Plone 4.0 through 5.2.1 allows users to perform unwanted SQL queries. (This is a problem in Zope.)
- risk 0.00cvss 8.8epss 0.01
plone.restapi in Plone 5.2.0 through 5.2.1 allows users with a certain privilege level to escalate their privileges up to the highest level.
- risk 0.49cvss 7.5epss 0.01
In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely.
- risk 0.51cvss 7.8epss 0.00
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of…
- risk 0.49cvss 7.5epss 0.03
In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
- risk 0.49cvss 7.5epss 0.02
Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identifiers in X.509 certificates.
- risk 0.49cvss 7.5epss 0.02
A Denial of Service vulnerability exists in the WRITE_C function in the msg_server.exe module in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04 when sending a crafted SAP Message Server packet to TCP ports 36NN and/or 39NN.
- risk 0.49cvss 7.5epss 0.01
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs…
- risk 0.49cvss 7.5epss 0.01
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
- risk 0.47cvss 7.2epss 0.04
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administrative users could upload an unsigned extension ZIP file containing executable code that is subsequently executed by the server.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.
- risk 0.47cvss 7.2epss 0.01
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
- risk 0.53cvss 7.5epss 0.12
Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
- risk 0.49cvss 7.5epss 0.02
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
- risk 0.50cvss 7.7epss 0.01
A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE Factory allowed local attackers to escalate privileges from user munge to root. This issue affects: SUSE Linux Enterprise Server 15 munge versions prior to…
- risk 0.49cvss 7.5epss 0.01
Server-side request forgery (SSRF) vulnerability in feed-proxy.php in extjs 5.0.0.
- risk 0.58cvss 8.8epss 0.05
In JFrog Artifactory 5.x and 6.x, insecure FreeMarker template processing leads to remote code execution, e.g., by modifying a .ssh/authorized_keys file. Patches are available for various versions between 5.11.8 and 6.16.0. The issue exists because use of the…
- risk 0.51cvss 7.8epss 0.00
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. If a user does not have direct access to the elevation feature through group policies, they are prompted to enter a…
- risk 0.51cvss 7.8epss 0.00
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will. When a user requests elevation using the AdminByRequest.exe interface, the interface communicates with the underlying…
- risk 0.51cvss 7.8epss 0.00
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
- risk 0.57cvss 8.8epss 0.04
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
- risk 0.60cvss 8.8epss 0.02
BabyGekko before 1.2.4 has SQL injection.
- risk 0.57cvss 8.8epss 0.03
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
- risk 0.50cvss 7.7epss 0.00
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE Linux Enterprise Server 15 SP1 trousers versions…
- risk 0.49cvss 7.5epss 0.02
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
- risk 0.50cvss 8.8epss 0.02
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.
- risk 0.50cvss 8.8epss 0.03
A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notification statement. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code…
- risk 0.50cvss 8.8epss 0.03
A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.
- risk 0.47cvss 7.2epss 0.02
Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.
- risk 0.39cvss 7.1epss 0.02
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value to an integer would set the Content-Length to 0 internally.…
- risk 0.57cvss 8.8epss 0.01
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
- risk 0.49cvss 7.5epss 0.02
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
- risk 0.57cvss 8.8epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.
- risk 0.47cvss 7.2epss 0.03
A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.
- risk 0.57cvss 8.8epss 0.01
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
- risk 0.51cvss 7.8epss 0.00
A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.
- risk 0.49cvss 7.5epss 0.01
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
- risk 0.49cvss 7.5epss 0.01
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build…
- risk 0.53cvss 8.1epss 0.01
The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This…
- risk 0.53cvss 8.1epss 0.01
The Enlightenment system service in Tizen allows an unprivileged process to fully control or capture windows, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
- risk 0.57cvss 8.8epss 0.01
The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
- risk 0.57cvss 8.8epss 0.01
The pkgmgr system service in Tizen allows an unprivileged process to perform package management actions, due to improper D-Bus security policy configurations. Such actions include installing, decrypting, and killing other packages. This affects Tizen before 5.0 M1, and…
- risk 0.49cvss 7.5epss 0.08
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
- risk 0.49cvss 7.5epss 0.04
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
- risk 0.42cvss 7.5epss 0.02
repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema.
- risk 0.49cvss 7.5epss 0.01
There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system…
- risk 0.49cvss 7.5epss 0.01
There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system…
- risk 0.47cvss 7.2epss 0.02
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the interface JSON field of the ping function.