| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19832 | Hig | 0.49 | 7.5 | 0.01 | Dec 31, 2019 | The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity. | ||
| CVE-2018-19831 | Hig | 0.49 | 7.5 | 0.01 | Dec 31, 2019 | The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity. | ||
| CVE-2018-19830 | Hig | 0.49 | 7.5 | 0.01 | Dec 31, 2019 | The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's… | ||
| CVE-2019-20176 | Hig | 0.00 | 7.5 | 0.04 | Dec 31, 2019 | In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. | ||
| CVE-2019-10229 | Hig | 0.57 | 8.8 | 0.01 | Dec 31, 2019 | An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) is set to Generic LDAP, an attacker is able to login as an existing user with an arbitrary password… | ||
| CVE-2019-20175 | Hig | 0.49 | 7.5 | 0.03 | Dec 31, 2019 | An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a… | ||
| CVE-2019-20172 | Hig | 0.00 | 7.8 | 0.00 | Dec 31, 2019 | Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only virtual address space, which allows local users to gain privileges by overwriting a return address that was found on the kernel stack. | ||
| CVE-2019-7479 | Hig | 0.47 | 7.2 | 0.01 | Dec 31, 2019 | A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earlier, Gen 6 version 6.2.7.4-32n, 6.5.1.4-4n, 6.5.2.3-4n, 6.5.3.3-3n, 6.2.7.10-3n, 6.4.1.0-3n,… | ||
| CVE-2018-20499 | Hig | 0.47 | 7.2 | 0.01 | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF. | ||
| CVE-2018-20494 | Hig | 0.49 | 7.5 | 0.02 | Dec 30, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control. | ||
| CVE-2013-2016 | Hig | 0.44 | 7.8 | 0.01 | Dec 30, 2019 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the… | ||
| CVE-2013-0264 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2019 | An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it. | ||
| CVE-2012-5663 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2019 | The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp). | ||
| CVE-2019-19032 | Hig | 0.56 | 8.1 | 0.05 | Dec 30, 2019 | XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload. | ||
| CVE-2019-19031 | Hig | 0.56 | 8.1 | 0.05 | Dec 30, 2019 | Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload. | ||
| CVE-2012-5645 | Hig | 0.49 | 7.5 | 0.04 | Dec 30, 2019 | A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption. | ||
| CVE-2019-20149 | — | Hig | 0.42 | 7.5 | 0.02 | Dec 30, 2019 | ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection… | |
| CVE-2019-19470 | Hig | 0.51 | 7.8 | 0.01 | Dec 30, 2019 | Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13. | ||
| CVE-2019-13465 | Hig | 0.56 | 8.6 | 0.01 | Dec 30, 2019 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When… | ||
| CVE-2019-20140 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c. | ||
| CVE-2019-19739 | Hig | 0.49 | 7.5 | 0.01 | Dec 30, 2019 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels. | ||
| CVE-2019-19737 | Hig | 0.57 | 8.8 | 0.00 | Dec 30, 2019 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks. | ||
| CVE-2019-19734 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. | ||
| CVE-2019-19732 | Hig | 0.47 | 7.2 | 0.01 | Dec 30, 2019 | translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically… | ||
| CVE-2019-17558 | — | Hig | 0.65 | 7.5 | 0.99 | KEV | Dec 30, 2019 | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain… |
| CVE-2019-20138 | Hig | 0.00 | 7.5 | 0.01 | Dec 30, 2019 | The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used. | ||
| CVE-2019-20094 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c. | ||
| CVE-2019-20090 | Hig | 0.51 | 7.8 | 0.01 | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp. | ||
| CVE-2019-20089 | Hig | 0.51 | 7.8 | 0.01 | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculation. | ||
| CVE-2019-20088 | Hig | 0.51 | 7.8 | 0.01 | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c. | ||
| CVE-2019-20087 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" feature. | ||
| CVE-2019-20086 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c. | ||
| CVE-2019-20085 | Hig | 0.71 | 7.5 | 0.96 | KEV | Dec 30, 2019 | TVT NVMS-1000 devices allow GET /.. Directory Traversal | |
| CVE-2019-20079 | Hig | 0.00 | 7.8 | 0.02 | Dec 30, 2019 | The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory. | ||
| CVE-2019-20074 | Hig | 0.57 | 8.8 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. | ||
| CVE-2019-20063 | Hig | 0.57 | 8.8 | 0.01 | Dec 29, 2019 | hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json. | ||
| CVE-2014-3136 | Hig | 0.60 | 8.8 | 0.03 | Dec 27, 2019 | Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors. | ||
| CVE-2012-4980 | Hig | 0.51 | 7.8 | 0.02 | Dec 27, 2019 | Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code. | ||
| CVE-2019-20048 | Hig | 0.47 | 7.2 | 0.06 | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM. | ||
| CVE-2019-20047 | Hig | 0.49 | 7.5 | 0.03 | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP… | ||
| CVE-2013-4985 | Hig | 0.52 | 7.5 | 0.09 | Dec 27, 2019 | Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream | ||
| CVE-2013-4975 | Hig | 0.61 | 8.8 | 0.12 | Dec 27, 2019 | Hikvision DS-2CD7153-E IP Camera has Privilege Escalation | ||
| CVE-2013-4859 | Hig | 0.56 | 8.1 | 0.07 | Dec 27, 2019 | INSTEON Hub 2242-222 lacks Web and API authentication | ||
| CVE-2013-4796 | Hig | 0.57 | 8.8 | 0.02 | Dec 27, 2019 | ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request | ||
| CVE-2019-16896 | Hig | 0.51 | 7.8 | 0.00 | Dec 27, 2019 | In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality. | ||
| CVE-2013-4695 | Hig | 0.54 | 7.8 | 0.05 | Dec 27, 2019 | Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution | ||
| CVE-2019-20014 | Hig | 0.57 | 8.8 | 0.01 | Dec 27, 2019 | An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. | ||
| CVE-2019-20011 | Hig | 0.57 | 8.8 | 0.01 | Dec 27, 2019 | An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c. | ||
| CVE-2019-20010 | Hig | 0.57 | 8.8 | 0.01 | Dec 27, 2019 | An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c. | ||
| CVE-2019-20006 | Hig | 0.49 | 7.5 | 0.01 | Dec 26, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault. |
- risk 0.49cvss 7.5epss 0.01
The NETM() function of a smart contract implementation for NewIntelTechMedia (NETM), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.
- risk 0.49cvss 7.5epss 0.01
The ToOwner() function of a smart contract implementation for Cryptbond Network (CBN), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.
- risk 0.49cvss 7.5epss 0.01
The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's…
- risk 0.00cvss 7.5epss 0.04
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the directory service (for synchronizing and authenticating users) is set to Generic LDAP, an attacker is able to login as an existing user with an arbitrary password…
- risk 0.49cvss 7.5epss 0.03
An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEMU process in the host system via a special SCSI_IOCTL_SEND_COMMAND. It hits an assertion that implies that the size of successful DMA transfers there must be a…
- risk 0.00cvss 7.8epss 0.00
Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only virtual address space, which allows local users to gain privileges by overwriting a return address that was found on the kernel stack.
- risk 0.47cvss 7.2epss 0.01
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SonicOS Gen 5 version 5.9.1.12-4o and earlier, Gen 6 version 6.2.7.4-32n, 6.5.1.4-4n, 6.5.2.3-4n, 6.5.3.3-3n, 6.2.7.10-3n, 6.4.1.0-3n,…
- risk 0.47cvss 7.2epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition before 11.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows SSRF.
- risk 0.49cvss 7.5epss 0.02
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It has Incorrect Access Control.
- risk 0.44cvss 7.8epss 0.01
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the…
- risk 0.49cvss 7.5epss 0.01
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
- risk 0.49cvss 7.5epss 0.01
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
- risk 0.56cvss 8.1epss 0.05
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The component is: XML Validate function. The attack vector is: Specially crafted XML payload.
- risk 0.56cvss 8.1epss 0.05
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.
- risk 0.49cvss 7.5epss 0.04
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.
- risk 0.42cvss 7.5epss 0.02
ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection…
- risk 0.51cvss 7.8epss 0.01
Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM for a local attacker. Affected product is TinyWall, all versions up to and including 2.1.12. Fixed in version 2.1.13.
- risk 0.56cvss 8.6epss 0.01
An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When…
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
- risk 0.49cvss 7.5epss 0.01
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent over cleartext channels.
- risk 0.57cvss 8.8epss 0.00
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sent in cross-site requests and potentially be used in cross-site request forgery attacks.
- risk 0.57cvss 8.8epss 0.01
_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection.
- risk 0.47cvss 7.2epss 0.01
translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly insert values from the aSortDir_0 and/or sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically…
- risk 0.65cvss 7.5epss 0.99
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain…
- risk 0.00cvss 7.5epss 0.01
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp.
- risk 0.51cvss 7.8epss 0.01
GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculation.
- risk 0.51cvss 7.8epss 0.01
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c.
- risk 0.57cvss 8.8epss 0.01
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" feature.
- risk 0.57cvss 8.8epss 0.01
GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c.
- risk 0.71cvss 7.5epss 0.96
TVT NVMS-1000 devices allow GET /.. Directory Traversal
- risk 0.00cvss 7.8epss 0.02
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
- risk 0.57cvss 8.8epss 0.01
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
- risk 0.57cvss 8.8epss 0.01
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
- risk 0.60cvss 8.8epss 0.03
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that change the admin password via unspecified vectors.
- risk 0.51cvss 7.8epss 0.02
Multiple stack-based buffer overflows in CFProfile.exe in Toshiba ConfigFree Utility 8.0.38 allow user-assisted attackers to execute arbitrary code.
- risk 0.47cvss 7.2epss 0.06
An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.
- risk 0.49cvss 7.5epss 0.03
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server configuration allows a remote unauthenticated attacker to retrieve the content of its own session files. Every session file contains the administrative LDAP…
- risk 0.52cvss 7.5epss 0.09
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
- risk 0.61cvss 8.8epss 0.12
Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
- risk 0.56cvss 8.1epss 0.07
INSTEON Hub 2242-222 lacks Web and API authentication
- risk 0.57cvss 8.8epss 0.02
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
- risk 0.51cvss 7.8epss 0.00
In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrative privileges of the user, allowing an arbitrary file write via a symbolic link attack with file restoration functionality.
- risk 0.54cvss 7.8epss 0.05
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content puts a pointer to the internal address of a larger block as xml->txt. This is later deallocated (using free), leading to a segmentation fault.