Search Results (344035 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-20648 1 Netgear 2 Rn42400, Rn42400 Firmware 2024-11-21 3.5 Low
NETGEAR RN42400 devices before 6.10.2 are affected by incorrect configuration of security settings.
CVE-2019-20647 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 5.7 Medium
NETGEAR RAX40 devices before 1.0.3.64 are affected by denial of service.
CVE-2019-20646 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 9.8 Critical
NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of administrative credentials.
CVE-2019-20645 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 4.8 Medium
NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.
CVE-2019-20644 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 4.8 Medium
NETGEAR RAX40 devices before 1.0.3.62 are affected by stored XSS.
CVE-2019-20643 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 7.5 High
NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information.
CVE-2019-20642 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 8.0 High
NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass.
CVE-2019-20641 1 Netgear 2 Rax40, Rax40 Firmware 2024-11-21 8.8 High
NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level.
CVE-2019-20640 1 Netgear 34 D3600, D3600 Firmware, D6000 and 31 more 2024-11-21 8.8 High
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, D6200 before 1.1.00.32, D7000 before 1.0.1.68, JR6150 before 1.0.1.18, PR2000 before 1.0.0.28, R6020 before 1.0.0.38, R6050 before 1.0.1.18, R6080 before 1.0.0.38, R6120 before 1.0.0.46, R6220 before 1.1.0.80, R6260 before 1.1.0.40, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900v2 before 1.2.0.36, WNR2020 before 1.1.0.62, and XR500 before 2.3.2.32.
CVE-2019-20639 1 Netgear 6 Rbk50, Rbk50 Firmware, Rbr50 and 3 more 2024-11-21 4.8 Medium
Certain NETGEAR devices are affected by stored XSS. This affects RBR50 before 2.3.5.30, RBS50 before 2.3.5.30, and RBK50 before 2.3.5.30.
CVE-2019-20638 1 Netgear 2 Mr1100, Mr1100 Firmware 2024-11-21 6.5 Medium
NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of administrative credentials.
CVE-2019-20637 4 Opensuse, Redhat, Varnish-cache and 1 more 5 Backports Sle, Leap, Enterprise Linux and 2 more 2024-11-21 7.5 High
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be disclosed from the connection workspace, such as data structures associated with previous requests within this connection or VCL-related temporary headers.
CVE-2019-20636 3 Linux, Netapp, Redhat 24 Linux Kernel, Cloud Backup, Fas 8300 and 21 more 2024-11-21 6.7 Medium
In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demonstrated by input_set_keycode, aka CID-cb222aed03d7.
CVE-2019-20635 1 Intland 1 Codebeamer 2024-11-21 6.1 Medium
codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class loader via computed fields.
CVE-2019-20634 1 Proofpoint 1 Email Protection 2024-11-21 3.7 Low
An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email headers, it is possible to build a copy-cat Machine Learning Classification model and extract insights from this model. The insights gathered allow an attacker to craft emails that receive preferable scores, with a goal of delivering malicious emails.
CVE-2019-20633 1 Gnu 1 Patch 2024-11-21 5.5 Medium
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
CVE-2019-20632 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_odf_delete_descriptor in odf/desc_private.c that can cause a denial of service via a crafted MP4 file.
CVE-2019-20631 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.
CVE-2019-20630 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer over-read in BS_ReadByte (called from gf_bs_read_bit) in utils/bitstream.c that can cause a denial of service via a crafted MP4 file.
CVE-2019-20629 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer over-read in gf_m2ts_process_pmt in media_tools/mpegts.c that can cause a denial of service via a crafted MP4 file.