Qualys Launches Free App for IT Asset Discovery and Inventory

Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database CVE-2019-15531PUBLISHED: 2019-08-23

GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

CVE-2019-10746PUBLISHED: 2019-08-23

mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

CVE-2019-10747PUBLISHED: 2019-08-23

set-value is vulnerable to Prototype Pollution in versions before 2.0.1 and version 3.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

CVE-2019-10750PUBLISHED: 2019-08-23

deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.

CVE-2019-10751PUBLISHED: 2019-08-23

All versions of the HTTPie package are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control.




Support the originator by clicking the read the rest link below.