CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-16446

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16445

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-16444

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a binary planting (default folder privilege escalation) vulnerability. Successful exploitation could lead to privilege escalation.

    Published: 19 Dec 2019
    4.8
    Medium

    CVE-2019-19900

    Last Modified: 21 Nov 2024

    An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized content type name, then have an editor execute scripting when creating content, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role with the "Administer content types" permission.

    Published: 19 Dec 2019
    7.2
    High

    CVE-2019-19902

    Last Modified: 21 Nov 2024

    An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.

    Published: 19 Dec 2019
    4.8
    Medium

    CVE-2019-19903

    Last Modified: 21 Nov 2024

    An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when viewing the list of file types, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role with the "Administer file types" permission.

    Published: 19 Dec 2019
    4.8
    Medium

    CVE-2019-19901

    Last Modified: 21 Nov 2024

    An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would be required to have the permission to create custom blocks, which is typically an administrative task.

    Published: 19 Dec 2019
    6.5
    Medium

    CVE-2019-15006

    Last Modified: 21 Nov 2024

    There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence Server and Confluence Data Center communicated with the Companion application via the atlassian-domain-for-localhost-connections-only.com domain name, the DNS A record of which points at 127.0.0.1. Additionally, a signed certificate for the domain was publicly distributed with the Companion application. An attacker in the position to control DNS resolution of their victim could carry out a man-in-the-middle (MITM) attack between Confluence Server (or Confluence Data Center) and the atlassian-domain-for-localhost-connections-only.com domain intended to be used with the Companion application. This certificate has been revoked, however, usage of the atlassian-domain-for-localhost-connections-only.com domain name was still present in Confluence Server and Confluence Data Center. An attacker could perform the described attack by denying their victim access to certificate revocation information, and carry out a man-in-the-middle (MITM) attack to observe files being edited using the Companion application and/or modify them, and access some limited user information.

    Published: 19 Dec 2019
    7.8
    High

    CVE-2019-7487

    Last Modified: 21 Nov 2024

    Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow code execution.

    Published: 19 Dec 2019
    6.5
    Medium

    CVE-2019-7484

    Last Modified: 21 Nov 2024

    Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

    Published: 19 Dec 2019
    8.8
    High

    CVE-2019-7485

    Last Modified: 21 Nov 2024

    Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

    Published: 19 Dec 2019
    8.8
    High

    CVE-2019-7486

    Last Modified: 21 Nov 2024

    Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-7483

    Last Modified: 31 Oct 2025

    In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-7482

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-19232

    Last Modified: 21 Nov 2024

    In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invoking sudo with a numeric uid that is not associated with any user. NOTE: The software maintainer believes that this is not a vulnerability because running a command via sudo as a user not present in the local password database is an intentional feature. Because this behavior surprised some users, sudo 1.8.30 introduced an option to enable/disable this behavior with the default being disabled. However, this does not change the fact that sudo was behaving as intended, and as documented, in earlier versions

    Published: 19 Dec 2019
    7.5
    High

    CVE-2019-19234

    Last Modified: 21 Nov 2024

    In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead of a password hash) is not considered, allowing an attacker (who has access to a Runas ALL sudoer account) to impersonate any blocked user. NOTE: The software maintainer believes that this CVE is not valid. Disabling local password authentication for a user is not the same as disabling all access to that user--the user may still be able to login via other means (ssh key, kerberos, etc). Both the Linux shadow(5) and passwd(1) manuals are clear on this. Indeed it is a valid use case to have local accounts that are _only_ accessible via sudo and that cannot be logged into with a password. Sudo 1.8.30 added an optional setting to check the _shell_ of the target user (not the encrypted password!) against the contents of /etc/shells but that is not the same thing as preventing access to users with an invalid password hash

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-19907

    Last Modified: 21 Nov 2024

    HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demonstrated by mishandling of an array copy during parsing of ICal data.

    Published: 19 Dec 2019
    9.8
    Critical

    CVE-2019-19899

    Last Modified: 21 Nov 2024

    Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-17390

    Last Modified: 21 Nov 2024

    An issue was discovered in the Outlook add-in in Pronestor Planner before 8.1.77. There is local privilege escalation in the Health Monitor service because PronestorHealthMonitor.exe access control is mishandled, aka PNB-2359.

    Published: 18 Dec 2019
    5.5
    Medium

    CVE-2019-19788

    Last Modified: 21 Nov 2024

    Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe it is possible to bypass the normal sandboxing attributes. This allows an attacker to make forced redirections without any user interaction from a third-party context.

    Published: 18 Dec 2019
    6.7
    Medium

    CVE-2019-11108

    Last Modified: 21 Nov 2024

    Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    6.8
    Medium

    CVE-2019-11086

    Last Modified: 21 Nov 2024

    Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

    Published: 18 Dec 2019
    6.7
    Medium

    CVE-2019-11110

    Last Modified: 21 Nov 2024

    Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    4.4
    Medium

    CVE-2019-11109

    Last Modified: 21 Nov 2024

    Logic issue in the subsystem for Intel(R) SPS before versions SPS_E5_04.01.04.275.0, SPS_SoC-X_04.00.04.100.0 and SPS_SoC-A_04.00.04.191.0 may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-11107

    Last Modified: 21 Nov 2024

    Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 18 Dec 2019
    6.7
    Medium

    CVE-2019-11106

    Last Modified: 21 Nov 2024

    Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    4.4
    Medium

    CVE-2019-11102

    Last Modified: 21 Nov 2024

    Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Dec 2019
    4.6
    Medium

    CVE-2019-11100

    Last Modified: 21 Nov 2024

    Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

    Published: 18 Dec 2019
    4.4
    Medium

    CVE-2019-11101

    Last Modified: 21 Nov 2024

    Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Dec 2019
    6.7
    Medium

    CVE-2019-11087

    Last Modified: 21 Nov 2024

    Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

    Published: 18 Dec 2019
    4.4
    Medium

    CVE-2019-0168

    Last Modified: 21 Nov 2024

    Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-0166

    Last Modified: 21 Nov 2024

    Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 18 Dec 2019
    4.4
    Medium

    CVE-2019-0165

    Last Modified: 21 Nov 2024

    Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.

    Published: 18 Dec 2019
    5.9
    Medium

    CVE-2019-11090

    Last Modified: 21 Nov 2024

    Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 18 Dec 2019
    8.1
    High

    CVE-2019-0131

    Last Modified: 21 Nov 2024

    Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-11103

    Last Modified: 21 Nov 2024

    Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-11097

    Last Modified: 21 Nov 2024

    Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-11104

    Last Modified: 21 Nov 2024

    Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-11131

    Last Modified: 21 Nov 2024

    Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 18 Dec 2019
    8.8
    High

    CVE-2019-11088

    Last Modified: 21 Nov 2024

    Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 18 Dec 2019
    6.7
    Medium

    CVE-2019-11105

    Last Modified: 21 Nov 2024

    Logic issue in subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to potentially enable escalation of privilege and information disclosure via local access.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-11147

    Last Modified: 21 Nov 2024

    Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo software for Intel(R) TXE before versions 3.1.70 and 4.0.20; INTEL-SA-00086 Detection Tool version 1.2.7.0 or before; INTEL-SA-00125 Detection Tool version 1.0.45.0 or before may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 18 Dec 2019
    8.4
    High

    CVE-2019-11132

    Last Modified: 21 Nov 2024

    Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access.

    Published: 18 Dec 2019
    8.8
    High

    CVE-2019-0169

    Last Modified: 21 Nov 2024

    Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.

    Published: 18 Dec 2019
    6.1
    Medium

    CVE-2019-18781

    Last Modified: 21 Nov 2024

    An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.

    Published: 18 Dec 2019
    8.8
    High

    CVE-2019-15589

    Last Modified: 21 Nov 2024

    An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

    Published: 18 Dec 2019
    5.3
    Medium

    CVE-2019-5487

    Last Modified: 21 Nov 2024

    An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-15575

    Last Modified: 21 Nov 2024

    A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-15576

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

    Published: 18 Dec 2019
    4.3
    Medium

    CVE-2019-15577

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

    Published: 18 Dec 2019