CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-19544

    Last Modified: 21 Nov 2024

    CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA several years after CA Automic Dollar Universe 5.3.3 reached End of Life (EOL) status on April 1, 2015.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-19518

    Last Modified: 21 Nov 2024

    CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-17076

    Last Modified: 21 Nov 2024

    An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2016-6589

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in the ITMS workflow process manager login window in Symantec IT Management Suite 8.0.

    Published: 8 Jan 2020
    7.8
    High

    CVE-2016-6590

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2014-2072

    Last Modified: 21 Nov 2024

    Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2014-1860

    Last Modified: 21 Nov 2024

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

    Published: 8 Jan 2020
    5.5
    Medium

    CVE-2020-0009

    Last Modified: 21 Nov 2024

    In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-142938932

    Published: 8 Jan 2020
    9.1
    Critical

    CVE-2014-1409

    Last Modified: 21 Nov 2024

    MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords

    Published: 8 Jan 2020
    7.1
    High

    CVE-2016-6591

    Last Modified: 21 Nov 2024

    A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabled, which could let a local malicious user bypass security restrictions.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-10778

    Last Modified: 21 Nov 2024

    devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.

    Published: 8 Jan 2020
    7.8
    High

    CVE-2016-6593

    Last Modified: 21 Nov 2024

    A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could let local malicious users execute arbitrary code.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2014-9908

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).

    Published: 8 Jan 2020
    7.8
    High

    CVE-2019-20362

    Last Modified: 21 Nov 2024

    In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2014-1598

    Last Modified: 21 Nov 2024

    centurystar 7.12 ActiveX Control has a Stack Buffer Overflow

    Published: 8 Jan 2020
    4.8
    Medium

    CVE-2014-1454

    Last Modified: 21 Nov 2024

    Pearson eSIS (Enterprise Student Information System) message board has stored XSS due to improper validation of user input

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2020-6170

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

    Published: 8 Jan 2020
    9.8
    Critical

    CVE-2019-20361

    Last Modified: 21 Nov 2024

    There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

    Published: 8 Jan 2020
    7.5
    High

    CVE-2019-20360

    Last Modified: 21 Nov 2024

    A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and access personally identifiable user information (PII) including names, addresses, IP addresses, and email addresses. Once an API key has been set to any meta key value from the wp_usermeta table, and the token is set to the corresponding MD5 hash of the meta key selected, one can make a request to the restricted endpoints, and thus access sensitive donor data.

    Published: 8 Jan 2020
    6.1
    Medium

    CVE-2020-6163

    Last Modified: 21 Nov 2024

    The WikibaseMediaInfo extension 1.35 for MediaWiki allows XSS because of improper template syntax within the PropertySuggestionsWidget template (in the templates/search/PropertySuggestionsWidget.mustache+dom file).

    Published: 8 Jan 2020
    5.5
    Medium

    CVE-2020-7063

    Last Modified: 21 Nov 2024

    In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more restrictive permissions. This may result in files having more lax permissions than intended when such archive is extracted.

    Published: 8 Jan 2020
    7.5
    High

    CVE-2020-1925

    Last Modified: 21 Nov 2024

    Apache Olingo versions 4.0.0 to 4.7.0 provide the AsyncRequestWrapperImpl class which reads a URL from the Location header, and then sends a GET or DELETE request to this URL. It may allow to implement a SSRF attack. If an attacker tricks a client to connect to a malicious server, the server can make the client call any URL including internal resources which are not directly accessible by the attacker.

    Published: 8 Jan 2020
    7.5
    High

    CVE-2020-36048

    Last Modified: 21 Nov 2024

    Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

    Published: 8 Jan 2020
    6.5
    Medium

    CVE-2019-17023

    Last Modified: 21 Nov 2024

    After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

    Published: 8 Jan 2020
    7.5
    High

    CVE-2020-36049

    Last Modified: 21 Nov 2024

    socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6589

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6591

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6592

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6593

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6595

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6596

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6597

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6598

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6599

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6600

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6601

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6602

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6603

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6604

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6605

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6606

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6607

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6594

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    —
    Unknown

    CVE-2020-6608

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 8 Jan 2020
    8.8
    High

    CVE-2019-17026

    Last Modified: 4 Nov 2025

    Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.

    Published: 8 Jan 2020
    7.8
    High

    CVE-2019-17148

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of root. Was ZDI-CAN-8685.

    Published: 7 Jan 2020
    5.4
    Medium

    CVE-2019-17151

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target must be within a chat session together with the attacker. The specific flaw exists within the parsing of a users profile. The issue lies in the failure to properly validate a users name. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-9302.

    Published: 7 Jan 2020
    9.8
    Critical

    CVE-2019-17146

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default. When parsing the SOAPAction request header, the process does not properly validate the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8458.

    Published: 7 Jan 2020
    8.8
    High

    CVE-2019-17147

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457.

    Published: 7 Jan 2020
    6.1
    Medium

    CVE-2019-18652

    Last Modified: 21 Nov 2024

    A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the victim's browser by tricking the victim into clicking on a crafted link. The payload was tested in Microsoft Internet Explorer 11.418.18362.0 and Microsoft Edge 44.18362.387.0 (Microsoft EdgeHTML 18.18362).

    Published: 7 Jan 2020