CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-19789

    Last Modified: 21 Nov 2024

    3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCWinNT before V2.4.7.54 allow a NULL pointer dereference.

    Published: 20 Dec 2019
    7.1
    High

    CVE-2019-19693

    Last Modified: 21 Nov 2024

    The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

    Published: 20 Dec 2019
    6.1
    Medium

    CVE-2019-19692

    Last Modified: 21 Nov 2024

    Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that the Japanese version of the product is NOT affected.

    Published: 20 Dec 2019
    4.9
    Medium

    CVE-2019-19691

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product console to exploit this vulnerability.

    Published: 20 Dec 2019
    9.8
    Critical

    CVE-2019-17571

    Last Modified: 28 May 2026

    Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2018-14553

    Last Modified: 21 Nov 2024

    gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

    Published: 20 Dec 2019
    7.2
    High

    CVE-2019-15695

    Last Modified: 21 Nov 2024

    TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can choose offset from start of the buffer to start writing his values, exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

    Published: 20 Dec 2019
    7.1
    High

    CVE-2019-16786

    Last Modified: 21 Nov 2024

    Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding first, followed by any further transfer codings, ending with chunked. Requests sent with: "Transfer-Encoding: gzip, chunked" would incorrectly get ignored, and the request would use a Content-Length header instead to determine the body size of the HTTP message. This could allow for Waitress to treat a single request as multiple requests in the case of HTTP pipelining. This issue is fixed in Waitress 1.4.0.

    Published: 20 Dec 2019
    7.2
    High

    CVE-2019-15691

    Last Modified: 21 Nov 2024

    TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception, ZRLEDecoder may try to access stack variable, which has been already freed during the process of stack unwinding. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

    Published: 20 Dec 2019
    7.2
    High

    CVE-2019-15694

    Last Modified: 21 Nov 2024

    TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

    Published: 20 Dec 2019
    7.1
    High

    CVE-2019-16785

    Last Modified: 21 Nov 2024

    Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if a front-end server does not parse header fields with an LF the same way as it does those with a CRLF it can lead to the front-end and the back-end server parsing the same HTTP message in two different ways. This can lead to a potential for HTTP request smuggling/splitting whereby Waitress may see two requests while the front-end server only sees a single HTTP message. This issue is fixed in Waitress 1.4.0.

    Published: 20 Dec 2019
    7.2
    High

    CVE-2019-15693

    Last Modified: 21 Nov 2024

    TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity.

    Published: 20 Dec 2019
    7.5
    High

    CVE-2019-19926

    Last Modified: 21 Nov 2024

    multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.

    Published: 20 Dec 2019
    8.8
    High

    CVE-2019-15690

    Last Modified: 15 Apr 2026

    LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c. An attacker sends cursor shapes with specially crafted dimensions, which can result in remote code execution.

    Published: 20 Dec 2019
    8.8
    High

    CVE-2019-19141

    Last Modified: 21 Nov 2024

    The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server has permissions. This allows remote code execution via a variety of methods, such as (on a default Ubuntu installation) creating a .ssh folder in the plex user's home directory via directory traversal, uploading an SSH authorized_keys file there, and logging into the host as the Plex user via SSH.

    Published: 19 Dec 2019
    9
    Critical

    CVE-2019-19915

    Last Modified: 21 Nov 2024

    The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save and /admin-ajax.php?action=eps_redirect_delete actions. This could result in a loss of site availability, malicious redirects, and user infections. This could also be exploited via CSRF.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16871

    Last Modified: 21 Nov 2024

    Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote Code Execution (as SYSTEM) via the Beckhoff ADS protocol.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-17527

    Last Modified: 21 Nov 2024

    dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Injection via the index.php?option=com_jsjobs&task=customfields.getfieldtitlebyfieldandfieldfo child parameter.

    Published: 19 Dec 2019
    7.8
    High

    CVE-2019-8253

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 19 Dec 2019
    7.8
    High

    CVE-2019-8254

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-8256

    Last Modified: 21 Nov 2024

    ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-8255

    Last Modified: 21 Nov 2024

    Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 19 Dec 2019
    4.3
    Medium

    CVE-2019-11294

    Last Modified: 21 Nov 2024

    Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.

    Published: 19 Dec 2019
    6.1
    Medium

    CVE-2019-19910

    Last Modified: 21 Nov 2024

    The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, as demonstrated by IMG onmouseover= (impact is XSS) and IMG src=http (impact is disclosing the client's IP address). This can occur within a talk page topical header that is viewed within a mobile (MobileFrontend) context.

    Published: 19 Dec 2019
    7.8
    High

    CVE-2019-18181

    Last Modified: 21 Nov 2024

    In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated users with read-only access to take actions that are otherwise restricted in the GUI.

    Published: 19 Dec 2019
    8.8
    High

    CVE-2019-19909

    Last Modified: 21 Nov 2024

    An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-19905

    Last Modified: 21 Nov 2024

    NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/sgid, and shared systems that allow users to upload their own configuration files.

    Published: 19 Dec 2019
    6.5
    Medium

    CVE-2019-19337

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.

    Published: 19 Dec 2019
    8.8
    High

    CVE-2019-17633

    Last Modified: 21 Nov 2024

    For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.

    Published: 19 Dec 2019
    6.1
    Medium

    CVE-2019-18955

    Last Modified: 21 Nov 2024

    The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed within changelog as of 02 Dec 2019.

    Published: 19 Dec 2019
    4.9
    Medium

    CVE-2019-18615

    Last Modified: 21 Nov 2024

    In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from the user's login password, OR 2. There are configlet builders that use the Device class and specify username and password explicitly Application logs are not accessible or visible from the CVP GUI. Application logs can only be read by authorized users with privileged access to the VM hosting the CVP application.

    Published: 19 Dec 2019
    8.1
    High

    CVE-2019-11780

    Last Modified: 21 Nov 2024

    Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 allows remote authenticated attackers to access sensitive information via crafted RPC requests, which could lead to privilege escalation.

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-16465

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16464

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16463

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16462

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-16461

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16460

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16459

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-16458

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-16457

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-16456

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16455

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16454

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16453

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16452

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16451

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16450

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-16449

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16448

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019