Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Robert Scott

#16802of 53,633
16Total CVSS
Vulnerabilities · 2
High
2
PT-2020-14702
8.5
2020-07-22
Bsdiff4 · Bsdiff4 · CVE-2020-15904
**Name of the Vulnerable Software and Affected Versions** bsdiff4 versions prior to 1.2.0 **Description** A buffer overflow in the patching routine allows an attacker to write to heap memory beyond allocated bounds via a crafted patch file. **Recommendations** For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue.
PT-2019-2290
7.5
2019-05-15
Cisco · Cisco Anyconnect Secure Mobility Client · CVE-2019-1853
**Name of the Vulnerable Software and Affected Versions** Cisco AnyConnect Secure Mobility Client for Linux (affected versions not specified) **Description** A vulnerability in the HostScan component could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The issue exists due to improper bounds checks, allowing an attacker to exploit it by crafting HTTP traffic for the affected component to download and process. A successful exploit could allow the attacker to read sensitive information on the affected system. The vulnerability is related to a buffer overflow in memory, which can be exploited using specially crafted HTTP traffic. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.