| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14899 | Hig | 0.48 | 7.4 | 0.01 | Dec 11, 2019 | A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct… | ||
| CVE-2013-4593 | — | Hig | 0.42 | 7.5 | 0.02 | Dec 11, 2019 | RubyGem omniauth-facebook has an access token security vulnerability | |
| CVE-2013-4245 | Hig | 0.47 | 7.3 | 0.01 | Dec 11, 2019 | Orca has arbitrary code execution due to insecure Python module load | ||
| CVE-2019-19720 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2019 | Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file. | ||
| CVE-2019-19707 | Hig | 0.49 | 7.5 | 0.01 | Dec 11, 2019 | On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets. | ||
| CVE-2019-5815 | Hig | 0.49 | 7.5 | 0.02 | Dec 11, 2019 | Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data. | ||
| CVE-2019-19604 | Hig | 0.51 | 7.8 | 0.04 | Dec 11, 2019 | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository. | ||
| CVE-2019-14889 | Hig | 0.57 | 8.8 | 0.03 | Dec 10, 2019 | A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way… | ||
| CVE-2019-1489 | Hig | 0.49 | 7.5 | 0.08 | Dec 10, 2019 | An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'. | ||
| CVE-2019-1485 | Hig | 0.49 | 7.5 | 0.08 | Dec 10, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | ||
| CVE-2019-1484 | Hig | 0.51 | 7.8 | 0.09 | Dec 10, 2019 | A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'. | ||
| CVE-2019-1483 | Hig | 0.51 | 7.8 | 0.02 | Dec 10, 2019 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID… | ||
| CVE-2019-1478 | Hig | 0.51 | 7.8 | 0.01 | Dec 10, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1477 | Hig | 0.51 | 7.8 | 0.01 | Dec 10, 2019 | An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'. | ||
| CVE-2019-1476 | Hig | 0.54 | 7.8 | 0.05 | Dec 10, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483. | ||
| CVE-2019-1471 | Hig | 0.54 | 8.2 | 0.08 | Dec 10, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'. | ||
| CVE-2019-1468 | Hig | 0.59 | 8.8 | 0.17 | Dec 10, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'. | ||
| CVE-2019-1462 | Hig | 0.52 | 7.8 | 0.18 | Dec 10, 2019 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. | ||
| CVE-2019-1458 | Hig | 0.78 | 7.8 | 0.74 | KEV | Dec 10, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. | |
| CVE-2019-1453 | Hig | 0.49 | 7.5 | 0.09 | Dec 10, 2019 | A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'. | ||
| CVE-2019-13764 | Hig | 0.58 | 8.8 | 0.06 | Dec 10, 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13747 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13741 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. | ||
| CVE-2019-13736 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2019 | Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | ||
| CVE-2019-13735 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2019 | Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | ||
| CVE-2019-13734 | Hig | 0.58 | 8.8 | 0.04 | Dec 10, 2019 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13732 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13730 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13729 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13728 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2019 | Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-13727 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page. | ||
| CVE-2019-13726 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2019 | Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | ||
| CVE-2019-13725 | Hig | 0.57 | 8.8 | 0.02 | Dec 10, 2019 | Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | ||
| CVE-2019-5843 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-5841 | Hig | 0.57 | 8.8 | 0.01 | Dec 10, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | ||
| CVE-2019-19702 | — | Hig | 0.42 | 7.5 | 0.01 | Dec 10, 2019 | The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the… | |
| CVE-2019-6183 | Hig | 0.49 | 7.5 | 0.02 | Dec 10, 2019 | A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not… | ||
| CVE-2013-4133 | Hig | 0.49 | 7.5 | 0.03 | Dec 10, 2019 | kde-workspace before 4.10.5 has a memory leak in plasma desktop | ||
| CVE-2013-4120 | Hig | 0.49 | 7.5 | 0.01 | Dec 10, 2019 | Katello has a Denial of Service vulnerability in API OAuth authentication | ||
| CVE-2013-2183 | Hig | 0.46 | 7.1 | 0.00 | Dec 10, 2019 | Monkey HTTP Daemon has local security bypass | ||
| CVE-2013-1793 | Hig | 0.49 | 7.5 | 0.01 | Dec 10, 2019 | openstack-utils openstack-db has insecure password creation | ||
| CVE-2013-0293 | Hig | 0.51 | 7.8 | 0.00 | Dec 10, 2019 | oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation | ||
| CVE-2019-4612 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2019 | IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523. | ||
| CVE-2015-7892 | Hig | 0.54 | 7.8 | 0.01 | Dec 9, 2019 | Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call. | ||
| CVE-2015-3424 | Hig | 0.57 | 8.8 | 0.02 | Dec 9, 2019 | SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter. | ||
| CVE-2014-0242 | Hig | 0.52 | 7.5 | 0.09 | Dec 9, 2019 | mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread. | ||
| CVE-2019-19603 | Hig | 0.01 | 7.5 | 0.08 | Dec 9, 2019 | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. | ||
| CVE-2015-0841 | Hig | 0.49 | 7.5 | 0.02 | Dec 9, 2019 | Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line. | ||
| CVE-2019-19687 | — | Hig | 0.50 | 8.8 | 0.02 | Dec 9, 2019 | OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other… | |
| CVE-2019-19685 | Hig | 0.57 | 8.8 | 0.01 | Dec 9, 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions. |
- risk 0.48cvss 7.4epss 0.01
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct…
- risk 0.42cvss 7.5epss 0.02
RubyGem omniauth-facebook has an access token security vulnerability
- risk 0.47cvss 7.3epss 0.01
Orca has arbitrary code execution due to insecure Python module load
- risk 0.57cvss 8.8epss 0.01
Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file.
- risk 0.49cvss 7.5epss 0.01
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.
- risk 0.49cvss 7.5epss 0.02
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
- risk 0.51cvss 7.8epss 0.04
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
- risk 0.57cvss 8.8epss 0.03
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way…
- risk 0.49cvss 7.5epss 0.08
An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'.
- risk 0.49cvss 7.5epss 0.08
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
- risk 0.51cvss 7.8epss 0.09
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.
- risk 0.51cvss 7.8epss 0.02
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'.
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while loading printer drivers, aka 'Windows Printer Service Elevation of Privilege Vulnerability'.
- risk 0.54cvss 7.8epss 0.05
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.
- risk 0.54cvss 8.2epss 0.08
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Remote Code Execution Vulnerability'.
- risk 0.59cvss 8.8epss 0.17
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
- risk 0.52cvss 7.8epss 0.18
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.
- risk 0.78cvss 7.8epss 0.74
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
- risk 0.49cvss 7.5epss 0.09
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
- risk 0.58cvss 8.8epss 0.06
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
- risk 0.57cvss 8.8epss 0.02
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
- risk 0.57cvss 8.8epss 0.02
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- risk 0.58cvss 8.8epss 0.04
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.02
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.02
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.02
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.02
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.42cvss 7.5epss 0.01
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the…
- risk 0.49cvss 7.5epss 0.02
A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not…
- risk 0.49cvss 7.5epss 0.03
kde-workspace before 4.10.5 has a memory leak in plasma desktop
- risk 0.49cvss 7.5epss 0.01
Katello has a Denial of Service vulnerability in API OAuth authentication
- risk 0.46cvss 7.1epss 0.00
Monkey HTTP Daemon has local security bypass
- risk 0.49cvss 7.5epss 0.01
openstack-utils openstack-db has insecure password creation
- risk 0.51cvss 7.8epss 0.00
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
- risk 0.57cvss 8.8epss 0.01
IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.
- risk 0.54cvss 7.8epss 0.01
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.
- risk 0.57cvss 8.8epss 0.02
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
- risk 0.52cvss 7.5epss 0.09
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
- risk 0.01cvss 7.5epss 0.08
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
- risk 0.49cvss 7.5epss 0.02
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.
- risk 0.50cvss 8.8epss 0.02
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other…
- risk 0.57cvss 8.8epss 0.01
RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.