The Most, Least Insecure US Cities for SMBs

Enterprise Vulnerabilities
From DHS/US-CERT’s National Vulnerability Database CVE-2019-19777
PUBLISHED: 2019-12-13

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.

CVE-2019-19778
PUBLISHED: 2019-12-13

An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.

CVE-2019-16777
PUBLISHED: 2019-12-13

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of pa…

CVE-2019-16775
PUBLISHED: 2019-12-13

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publi…

CVE-2019-16776
PUBLISHED: 2019-12-13

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain…

Read More HERE

Leave a Reply