Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2019
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
CVSS Score
8.8
EPSS Score
0.02
Published
2019-11-07
gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-11-07
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
CVSS Score
6.5
EPSS Score
0.006
Published
2019-11-07
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.
CVSS Score
9.8
EPSS Score
0.004
Published
2019-11-07
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
CVSS Score
4.8
EPSS Score
0.006
Published
2019-11-07
Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.
CVSS Score
6.5
EPSS Score
0.004
Published
2019-11-07
Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.
CVSS Score
5.0
EPSS Score
0.002
Published
2019-11-07
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
CVSS Score
6.1
EPSS Score
0.007
Published
2019-11-07
An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-11-07
A wrong type is used for a return value from strlen in WebKit in Google Chrome before Blink M12 on 64-bit platforms.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-11-07


Contact Us

Shodan ® - All rights reserved