CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2019-18833

    Last Modified: 21 Nov 2024

    Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key of the media content which is shared between a ClickShare Button and a ClickShare Base Unit is randomly generated for each new session and communicated over a TLS connection. An attacker who is able to perform a Man-in-the-Middle attack between the TLS connection, is able to obtain the encryption key.

    Published: 17 Dec 2019
    8.1
    High

    CVE-2019-18832

    Last Modified: 21 Nov 2024

    Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Button implements encryption at rest which uses a one-time programmable (OTP) AES encryption key. This key is shared across all ClickShare Buttons of model R9861500D01.

    Published: 17 Dec 2019
    7.8
    High

    CVE-2019-18829

    Last Modified: 21 Nov 2024

    Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed 'Clickshare_For_Windows.exe' binary on the ClickShare Button (R9861500D01) loads a number of DLL files dynamically without verifying their integrity.

    Published: 17 Dec 2019
    7.5
    High

    CVE-2019-18825

    Last Modified: 21 Nov 2024

    Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Base Unit implements encryption at rest using encryption keys which are shared across all ClickShare Base Units of models CS-100 & CSE-200.

    Published: 17 Dec 2019
    6.6
    Medium

    CVE-2019-18824

    Last Modified: 21 Nov 2024

    Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Button does not verify the integrity of the mutable content on the UBIFS partition before being used.

    Published: 17 Dec 2019
    6.5
    Medium

    CVE-2019-19830

    Last Modified: 21 Nov 2024

    _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.

    Published: 17 Dec 2019
    4.3
    Medium

    CVE-2019-15011

    Last Modified: 21 Nov 2024

    The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check.

    Published: 17 Dec 2019
    6.5
    Medium

    CVE-2017-18107

    Last Modified: 21 Nov 2024

    Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.

    Published: 17 Dec 2019
    7.8
    High

    CVE-2019-19814

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.

    Published: 17 Dec 2019
    7.8
    High

    CVE-2019-19816

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandled.

    Published: 17 Dec 2019
    7.5
    High

    CVE-2019-19880

    Last Modified: 21 Nov 2024

    exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.

    Published: 17 Dec 2019
    5.5
    Medium

    CVE-2019-19813

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c, __btrfs_qgroup_free_meta in fs/btrfs/qgroup.c, and btrfs_insert_delayed_items in fs/btrfs/delayed-inode.c.

    Published: 17 Dec 2019
    5.5
    Medium

    CVE-2019-19815

    Last Modified: 21 Nov 2024

    In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.

    Published: 17 Dec 2019
    8.1
    High

    CVE-2019-19847

    Last Modified: 21 Nov 2024

    Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.

    Published: 17 Dec 2019
    8.8
    High

    CVE-2019-13767

    Last Modified: 21 Nov 2024

    Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 17 Dec 2019
    9.8
    Critical

    CVE-2019-19826

    Last Modified: 21 Nov 2024

    The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_handler_filter_dynamic_fields.inc, as demonstrated by PHP object injection, involving a field_names object and an Archive_Tar object, for file deletion. Code execution might also be possible.

    Published: 16 Dec 2019
    5.3
    Medium

    CVE-2019-12413

    Last Modified: 21 Nov 2024

    In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query.

    Published: 16 Dec 2019
    5.3
    Medium

    CVE-2019-12414

    Last Modified: 21 Nov 2024

    In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab

    Published: 16 Dec 2019
    6.5
    Medium

    CVE-2019-5259

    Last Modified: 21 Nov 2024

    There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful exploit could cause an information disclosure condition.

    Published: 16 Dec 2019
    8.8
    High

    CVE-2019-18191

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template could allow an authenticated entity with certain unrestricted AWS execution privileges to escalate to full privileges within the target AWS account.

    Published: 16 Dec 2019
    5.4
    Medium

    CVE-2019-13182

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.

    Published: 16 Dec 2019
    6.5
    Medium

    CVE-2019-13181

    Last Modified: 21 Nov 2024

    A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

    Published: 16 Dec 2019
    2.6
    Low

    CVE-2019-16778

    Last Modified: 21 Nov 2024

    In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument is int32. In this case data_size and num_segments fields are truncated from int64 to int32 and can produce negative numbers, resulting in accessing out of bounds heap memory. This is unlikely to be exploitable and was detected and fixed internally in TensorFlow 1.15 and 2.0.

    Published: 16 Dec 2019
    5.5
    Medium

    CVE-2019-19817

    Last Modified: 21 Nov 2024

    The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.

    Published: 16 Dec 2019
    5.5
    Medium

    CVE-2019-19819

    Last Modified: 21 Nov 2024

    The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-19820

    Last Modified: 21 Nov 2024

    An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read primitive.

    Published: 16 Dec 2019
    5.5
    Medium

    CVE-2019-19818

    Last Modified: 21 Nov 2024

    The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.

    Published: 16 Dec 2019
    6.8
    Medium

    CVE-2019-18579

    Last Modified: 21 Nov 2024

    Settings for the Dell XPS 13 2-in-1 (7390) BIOS versions prior to 1.1.3 contain a configuration vulnerability. The BIOS configuration for the "Enable Thunderbolt (and PCIe behind TBT) pre-boot modules" setting is enabled by default. A local unauthenticated attacker with physical access to a user's system can obtain read or write access to main memory via a DMA attack during platform boot.

    Published: 16 Dec 2019
    5.8
    Medium

    CVE-2019-16779

    Last Modified: 21 Nov 2024

    In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.

    Published: 16 Dec 2019
    9.8
    Critical

    CVE-2019-18261

    Last Modified: 21 Nov 2024

    In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the software does not implement sufficient measures to prevent multiple failed authentication attempts within in a short time frame, making it more susceptible to brute force attacks.

    Published: 16 Dec 2019
    8.1
    High

    CVE-2019-13533

    Last Modified: 2 Jun 2026

    In Omron PLC CJ series, all versions, and Omron PLC CS series, all versions, an attacker could monitor traffic between the PLC and the controller and replay requests that could result in the opening and closing of industrial valves.

    Published: 16 Dec 2019
    9.8
    Critical

    CVE-2019-18269

    Last Modified: 2 Jun 2026

    Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability.

    Published: 16 Dec 2019
    9.8
    Critical

    CVE-2019-18259

    Last Modified: 21 Nov 2024

    In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages or execute commands.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-0134

    Last Modified: 21 Nov 2024

    Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially execute code at an elevated level of privilege.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-0159

    Last Modified: 21 Nov 2024

    Insufficient memory protection in the Linux Administrative Tools for Intel(R) Network Adapters before version 24.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    5.5
    Medium

    CVE-2019-11096

    Last Modified: 21 Nov 2024

    Insufficient memory protection for Intel(R) Ethernet I218 Adapter driver for Windows* 10 before version 24.1 may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 16 Dec 2019
    5.5
    Medium

    CVE-2019-11165

    Last Modified: 21 Nov 2024

    Improper conditions check in the Linux kernel driver for the Intel(R) FPGA SDK for OpenCL(TM) Pro Edition before version 19.4 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 16 Dec 2019
    6.7
    Medium

    CVE-2019-11157

    Last Modified: 21 Nov 2024

    Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-14568

    Last Modified: 21 Nov 2024

    Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    6.7
    Medium

    CVE-2019-14612

    Last Modified: 21 Nov 2024

    Out of bounds write in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    6.7
    Medium

    CVE-2019-14611

    Last Modified: 21 Nov 2024

    Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    6.7
    Medium

    CVE-2019-14609

    Last Modified: 21 Nov 2024

    Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-14610

    Last Modified: 21 Nov 2024

    Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-14608

    Last Modified: 21 Nov 2024

    Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    5.3
    Medium

    CVE-2019-14607

    Last Modified: 21 Nov 2024

    Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-14605

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-14603

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    5.5
    Medium

    CVE-2019-14604

    Last Modified: 21 Nov 2024

    Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local access.

    Published: 16 Dec 2019
    7.8
    High

    CVE-2019-14599

    Last Modified: 21 Nov 2024

    Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 16 Dec 2019
    6.5
    Medium

    CVE-2019-19743

    Last Modified: 21 Nov 2024

    On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.

    Published: 16 Dec 2019