NCCIC Weekly Vulnerability Summary: December 30, 2019.pdf

30-Dec-19.pdf
Preview of NCCIC Weekly Vulnerability Summary: December 30, 2019
🔗 Source: cyberneticgi.com
📊 Size: 744 KB
👤 Author: Manish Chaudhari
⬇️ Downloads: 120

Summary

# Vulnerability Summary for the Week of December 30, 2019

## Overview
This bulletin summarizes newly reported vulnerabilities from the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) for the week ending December 30, 2019. It includes critical, high, medium, and low-severity vulnerabilities across various software products and systems.

## Critical Vulnerabilities:
- Citrix Application Delivery Controller/Gateway: A Directory Traversal issue allows an attacker to traverse directory structures, potentially leading to unauthorized access or data exfiltration. (CVSS: 7.5)
- Freeciv: A denial-of-service (DoS) vulnerability in the server component can be exploited by sending carefully crafted packets, resulting in memory exhaustion or CPU consumption. (CVSS: 7.8)
- Magnolia CMS: Multiple access bypass vulnerabilities allow unauthorized users to gain elevated privileges. (CVSS: 7.5)
- Collabtive (Open Dynamics): Incorrect access control can enable an attacker to perform actions they should not be able to, potentially leading to data breaches or system compromise. (CVSS: 7.5)
- php-shellcommand: A command injection vulnerability allows remote attackers to execute arbitrary code, posing a severe risk to system integrity. (CVSS: 10)
- Senkas Kolibri: Buffer overflow vulnerabilities can be exploited to execute arbitrary code via crafted URIs, leading to potential system takeover. (CVSS: 7.5)
- SQLite: A stack unwinding issue in the `selectExpander` function may allow attackers to execute malicious code or cause a denial of service. (CVSS: 7.5)
- WordPress: Mishandling of the HTML5 colon named entity in `wpksesbad_protocol` can enable attackers to bypass input sanitization, potentially leading to cross-site scripting (XSS) attacks. (CVSS: 7.5)
- ClickHouse (Yandex): Out-of-bounds read, write, and integer underflow vulnerabilities can be exploited for remote code execution or denial of service via the native protocol. (CVSS: 7.5)

## Medium Vulnerabilities:
- Bolt: Cross-site scripting (XSS) vulnerabilities through the slug, teaser, or title parameters in the `editcontent/pages` endpoint. (CVSS: 4.3)
- GeniXCMS: Cross-site scripting (XSS) via the dbuser or dbhost parameter during the installation process. (CVSS: 4.3)
- GNU LibreDWG (multiple versions): Several memory management issues, including use-after-free, heap-based buffer overreads, and double-free vulnerabilities, can be exploited for potential code execution or denial of service. (CVSS scores range from 4.3 to 6.8)
- GPAC (version 0.8.0 and 0.9.0-development-20191109): Multiple NULL pointer dereferences, use-after-free issues, and buffer overflow vulnerabilities across various components of the software. (CVSS scores range from 4.3 to 4.3)

Description

A weekly summary from NIST's National Vulnerability Database (NVD), detailing newly recorded vulnerabilities, categorized by severity, using CVE and CVSS standards.

Technical Information

  • File Format: PDF
  • File Size: 744 KB
  • Pages: 11
  • Language: EN
  • Author: Manish Chaudhari
  • Total Downloads: 120
  • Last Updated: 2 hours ago

Document Overview

This PDF document about NCCIC Weekly Vulnerability Summary: December 30, 2019 provides comprehensive information and guidance. Whether you're a beginner or advanced user, this resource offers valuable insights into NCCIC Weekly Vulnerability Summary: December 30, 2019.

Related Topics

If you're interested in NCCIC Weekly Vulnerability Summary: December 30, 2019, you might also want to explore:

Download NCCIC Weekly Vulnerability Summary: December 30, 2019 eBooks for free and learn more about NCCIC Weekly Vulnerability Summary: December 30, 2019. These books contain exercises and tutorials to improve your practical skills, at all levels!

Not satisfied with this document? We have related documents to NCCIC Weekly Vulnerability Summary: December 30, 2019, try searching with similar keywords: NCCIC Weekly Vulnerability Summary: December 30, 2019, NCCIC Weekly Vulnerability Summary: October 21, 2021, Nccic, The Vulnerability of Casuarina-backed Sea Turtle Nesting Beaches to Erosion (14-10-2019), Vulnerability Summary, 2019 Autumn Series – 29th December 2019 – Overall Results, 3-RP 1059-1554-PUBLISHED- ON-12-13-2019-12-14- 2019-12-15-2019-BY-A nn-Galloway Pdf, Treasures Grade 5 Weekly Assessment Includes Leveled Weekly Tests

You can download PDF versions of the user's guide, manuals and ebooks about NCCIC Weekly Vulnerability Summary: December 30, 2019, you can also find and download for free A free online manual (notices) with beginner and intermediate, Downloads Documentation, You can download PDF files (or DOC and PPT) about NCCIC Weekly Vulnerability Summary: December 30, 2019 for free, but please respect copyrighted ebooks.