CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-5469

    Last Modified: 21 Nov 2024

    An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

    Published: 18 Dec 2019
    6.5
    Medium

    CVE-2019-15580

    Last Modified: 21 Nov 2024

    An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-15596

    Last Modified: 21 Nov 2024

    A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.

    Published: 18 Dec 2019
    8.8
    High

    CVE-2019-5486

    Last Modified: 21 Nov 2024

    A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-15598

    Last Modified: 21 Nov 2024

    A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-15599

    Last Modified: 21 Nov 2024

    A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-15600

    Last Modified: 21 Nov 2024

    A Path traversal exists in http_server which allows an attacker to read arbitrary system files.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-19724

    Last Modified: 21 Nov 2024

    Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

    Published: 18 Dec 2019
    9.1
    Critical

    CVE-2019-5078

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-5075

    Last Modified: 21 Nov 2024

    An exploitable stack buffer overflow vulnerability exists in the command line utility getcouplerdetails of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets sent to the iocheckd service "I/O-Check" can cause a stack buffer overflow in the sub-process getcouplerdetails, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    5.3
    Medium

    CVE-2019-5073

    Last Modified: 21 Nov 2024

    An exploitable information exposure vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause an external tool to fail, resulting in uninitialized stack data to be copied to the response packet buffer. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    6.5
    Medium

    CVE-2019-15591

    Last Modified: 21 Nov 2024

    An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

    Published: 18 Dec 2019
    8.8
    High

    CVE-2019-18573

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a Session Fixation vulnerability. An authenticated malicious local user could potentially exploit this vulnerability as the session token is exposed as part of the URL. A remote attacker can gain access to victim’s session and perform arbitrary actions with privileges of the user within the compromised session.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-18572

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain an Improper Authentication vulnerability. A Java JMX agent running on the remote host is configured with plain text password authentication. An unauthenticated remote attacker can connect to the JMX agent and monitor and manage the Java application.

    Published: 18 Dec 2019
    5.4
    Medium

    CVE-2019-18571

    Last Modified: 21 Nov 2024

    The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.

    Published: 18 Dec 2019
    9.1
    Critical

    CVE-2019-5080

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A single packet can cause a denial of service and weaken credentials resulting in the default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-5079

    Last Modified: 21 Nov 2024

    An exploitable heap buffer overflow vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    7.1
    High

    CVE-2019-18996

    Last Modified: 21 Nov 2024

    Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.

    Published: 18 Dec 2019
    4.3
    Medium

    CVE-2019-18997

    Last Modified: 21 Nov 2024

    The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.

    Published: 18 Dec 2019
    3.9
    Low

    CVE-2019-18994

    Last Modified: 21 Nov 2024

    Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.

    Published: 18 Dec 2019
    4.3
    Medium

    CVE-2019-18995

    Last Modified: 21 Nov 2024

    The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-5081

    Last Modified: 21 Nov 2024

    An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow, potentially resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    9.1
    Critical

    CVE-2019-5077

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200 Firmware versions 03.01.07(13) and 03.00.39(12), and WAGO PFC 100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a denial of service, resulting in the device entering an error state where it ceases all network communications. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-11995

    Last Modified: 21 Nov 2024

    Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1, 1.2.4.0, the resolution will be to upgrade to 1.2.4.2 RP3 HF1 Customers are requested to upgrade to the updated versions or contact HPE support for further assistance.

    Published: 18 Dec 2019
    5.4
    Medium

    CVE-2019-18267

    Last Modified: 21 Nov 2024

    An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-5074

    Last Modified: 21 Nov 2024

    An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a stack buffer overflow, resulting in code execution. An attacker can send unauthenticated packets to trigger this vulnerability.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-19890

    Last Modified: 21 Nov 2024

    An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-19889

    Last Modified: 21 Nov 2024

    An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf.

    Published: 18 Dec 2019
    6.5
    Medium

    CVE-2019-19887

    Last Modified: 21 Nov 2024

    bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode.

    Published: 18 Dec 2019
    6.5
    Medium

    CVE-2019-19888

    Last Modified: 21 Nov 2024

    jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-19689

    Last Modified: 21 Nov 2024

    Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-19690

    Last Modified: 21 Nov 2024

    Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-19688

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-8785

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-8787

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A remote attacker may be able to leak memory.

    Published: 18 Dec 2019
    5.5
    Medium

    CVE-2019-8794

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-8797

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.

    Published: 18 Dec 2019
    5.5
    Medium

    CVE-2019-8798

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with system privileges.

    Published: 18 Dec 2019
    8.4
    High

    CVE-2019-8803

    Last Modified: 21 Nov 2024

    An authentication issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. A local attacker may be able to login to the account of a previously logged in user without valid credentials..

    Published: 18 Dec 2019
    5.5
    Medium

    CVE-2019-8817

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.

    Published: 18 Dec 2019
    9.8
    Critical

    CVE-2019-8849

    Last Modified: 21 Nov 2024

    The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.

    Published: 18 Dec 2019
    6.8
    Medium

    CVE-2019-8760

    Last Modified: 21 Nov 2024

    This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-8786

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to execute arbitrary code with kernel privileges.

    Published: 18 Dec 2019
    7.5
    High

    CVE-2019-8788

    Last Modified: 21 Nov 2024

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.

    Published: 18 Dec 2019
    8.8
    High

    CVE-2019-8792

    Last Modified: 21 Nov 2024

    An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

    Published: 18 Dec 2019
    5.5
    Medium

    CVE-2019-8793

    Last Modified: 21 Nov 2024

    A consistency issue existed in deciding when to show the screen recording indicator. The issue was resolved with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2. A local user may be able to record the screen without a visible screen recording indicator.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-8800

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrary code execution.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-8801

    Last Modified: 21 Nov 2024

    A dynamic library loading issue existed in iTunes setup. This was addressed with improved path searching. This issue is fixed in macOS Catalina 10.15.1, iTunes for Windows 12.10.2. Running the iTunes installer in an untrusted directory may result in arbitrary code execution.

    Published: 18 Dec 2019
    5.7
    Medium

    CVE-2019-8804

    Last Modified: 21 Nov 2024

    An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

    Published: 18 Dec 2019
    7.8
    High

    CVE-2019-8807

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.1. An application may be able to execute arbitrary code with system privileges.

    Published: 18 Dec 2019