CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-19786

    Last Modified: 21 Nov 2024

    ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.

    Published: 13 Dec 2019
    7.8
    High

    CVE-2019-19787

    Last Modified: 21 Nov 2024

    ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.

    Published: 13 Dec 2019
    6.5
    Medium

    CVE-2019-5290

    Last Modified: 21 Nov 2024

    Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations on affected devices. Because the pointer in the program is not processed properly, the vulnerability can be exploited to cause the device to be abnormal.

    Published: 13 Dec 2019
    7.4
    High

    CVE-2019-5248

    Last Modified: 21 Nov 2024

    CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on the target device.

    Published: 13 Dec 2019
    5.9
    Medium

    CVE-2019-5291

    Last Modified: 21 Nov 2024

    Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.

    Published: 13 Dec 2019
    5.5
    Medium

    CVE-2019-5251

    Last Modified: 21 Nov 2024

    There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.

    Published: 13 Dec 2019
    7.8
    High

    CVE-2019-5250

    Last Modified: 21 Nov 2024

    Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function.

    Published: 13 Dec 2019
    7.5
    High

    CVE-2019-19397

    Last Modified: 21 Nov 2024

    There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. Attackers may exploit the vulnerability to cause information leaks.

    Published: 13 Dec 2019
    6.1
    Medium

    CVE-2019-17599

    Last Modified: 21 Nov 2024

    The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via the from or till parameter (and/or the quiz_id parameter). The component is: admin/quiz-options-page.php. The attack vector is: When the Administrator is logged in, a reflected XSS may execute upon a click on a malicious URL.

    Published: 13 Dec 2019
    7.5
    High

    CVE-2014-3495

    Last Modified: 21 Nov 2024

    duplicity 0.6.24 has improper verification of SSL certificates

    Published: 13 Dec 2019
    4.4
    Medium

    CVE-2014-2387

    Last Modified: 21 Nov 2024

    Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities

    Published: 13 Dec 2019
    7.8
    High

    CVE-2014-1867

    Last Modified: 21 Nov 2024

    suPHP before 0.7.2 source-highlighting feature allows security bypass which could lead to arbitrary code execution

    Published: 13 Dec 2019
    7.8
    High

    CVE-2019-19501

    Last Modified: 21 Nov 2024

    VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe.

    Published: 13 Dec 2019
    7.5
    High

    CVE-2019-13347

    Last Modified: 21 Nov 2024

    An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by browsing the affected Jira/Confluence/Bitbucket/Bamboo instance, even when the applicable configuration option of the plugin has been disabled ("Reactivate inactive users"). Exploiting this vulnerability requires an attacker to be authorized by the identity provider and requires that the plugin's configuration option "User Update Method" have the "Update from SAML Attributes" value.

    Published: 13 Dec 2019
    9.8
    Critical

    CVE-2019-19782

    Last Modified: 21 Nov 2024

    The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.

    Published: 13 Dec 2019
    8.8
    High

    CVE-2019-19778

    Last Modified: 24 Apr 2026

    An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.

    Published: 13 Dec 2019
    8.8
    High

    CVE-2019-19777

    Last Modified: 24 Apr 2026

    stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.

    Published: 13 Dec 2019
    5.3
    Medium

    CVE-2019-19722

    Last Modified: 21 Nov 2024

    In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.

    Published: 13 Dec 2019
    5.5
    Medium

    CVE-2019-19797

    Last Modified: 21 Nov 2024

    read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.

    Published: 13 Dec 2019
    7.4
    High

    CVE-2019-14868

    Last Modified: 21 Nov 2024

    In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely.

    Published: 13 Dec 2019
    4.4
    Medium

    CVE-2019-16774

    Last Modified: 21 Nov 2024

    In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.

    Published: 12 Dec 2019
    6.5
    Medium

    CVE-2019-5062

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected clients with valid 802.11w sessions. By simulating an incomplete new association, an attacker can trigger a deauthentication against stations using 802.11w, resulting in a denial of service.

    Published: 12 Dec 2019
    6.5
    Medium

    CVE-2019-5061

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.

    Published: 12 Dec 2019
    8.1
    High

    CVE-2019-5144

    Last Modified: 21 Nov 2024

    An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Software SDK 7.10.2. A specially crafted jp2 file can cause a heap overflow, which can result in remote code execution. An attacker could provide a malformed file to the victim to trigger this vulnerability.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-3951

    Last Modified: 21 Nov 2024

    Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) due to a stack-based buffer overflow when handling IOCTL 70533 RPC messages.

    Published: 12 Dec 2019
    8.8
    High

    CVE-2019-19771

    Last Modified: 21 Nov 2024

    The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash package name. In particular, the Trojan horse finds and exfiltrates cryptocurrency wallets.

    Published: 12 Dec 2019
    5.3
    Medium

    CVE-2019-18333

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain access to filenames on the server by sending specifically crafted packets to 8090/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    5.3
    Medium

    CVE-2019-18335

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to gain access to logs and configuration files by sending specifically crafted packets to 80/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    5.3
    Medium

    CVE-2019-18341

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) contains an authentication bypass vulnerability. A remote attacker with network access to the CCS server could exploit this vulnerability to read data from the EDIR directory (for example, the list of all configured stations).

    Published: 12 Dec 2019
    5.3
    Medium

    CVE-2019-18332

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain access to directory listings of the server by sending specifically crafted packets to 80/tcp, 8095/tcp or 8080/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18337

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an authentication bypass vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. A remote attacker with network access to the CCS server could exploit this vulnerability to read the CCS users database, including the passwords of all users in obfuscated cleartext.

    Published: 12 Dec 2019
    5.5
    Medium

    CVE-2019-18340

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) (All versions >= V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0). Both the SiVMS/SiNVR Video Server and the Control Center Server (CCS) store user and device passwords by applying weak cryptography. A local attacker could exploit this vulnerability to extract the passwords from the user database and/or the device configuration files to conduct further attacks.

    Published: 12 Dec 2019
    5.3
    Medium

    CVE-2019-18334

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could be able to enumerate valid user names by sending specifically crafted packets to 8090/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    7.7
    High

    CVE-2019-18338

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker with network access to the CCS server could exploit this vulnerability to list arbitrary directories or read files outside of the CCS application context.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18339

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port 5401/tcp) of the SiVMS/SiNVR Video Server contains an authentication bypass vulnerability, even when properly configured with enforced authentication. A remote attacker with network access to the Video Server could exploit this vulnerability to read the SiVMS/SiNVR users database, including the passwords of all users in obfuscated cleartext.

    Published: 12 Dec 2019
    9.9
    Critical

    CVE-2019-18342

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default port 22/tcp) of the Control Center Server (CCS) does not properly limit its capabilities to the specified purpose. In conjunction with CVE-2019-18341, an unauthenticated remote attacker with network access to the CCS server could exploit this vulnerability to read or delete arbitrary files, or access other resources on the same server.

    Published: 12 Dec 2019
    7.5
    High

    CVE-2019-18310

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 7061/tcp. This vulnerability is independent from CVE-2019-18311. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18315

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could gain remote code execution by sending specifically crafted packets to 8888/tcp. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.1
    Critical

    CVE-2019-18322

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18321. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18324

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18329

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    7.5
    High

    CVE-2019-18317

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18318 and CVE-2019-18319. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    7.5
    High

    CVE-2019-18319

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). An attacker with network access to the Application Server could cause a Denial-of-Service condition by sending specifically crafted objects via RMI. This vulnerability is independent from CVE-2019-18317 and CVE-2019-18318. Please note that an attacker needs to have network access to the Application Server in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.1
    Critical

    CVE-2019-18321

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could be able to read and write arbitrary files on the local file system by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18322. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18323

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18325

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18326, CVE-2019-18327, CVE-2019-18328, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    9.8
    Critical

    CVE-2019-18328

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server can cause a Denial-of-Service condition and potentially gain remote code execution by sending specifically crafted packets to 5010/tcp. This vulnerability is independent from CVE-2019-18323, CVE-2019-18324, CVE-2019-18325, CVE-2019-18326, CVE-2019-18327, CVE-2019-18329, and CVE-2019-18330. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    7.5
    High

    CVE-2019-18307

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could trigger a Denial-of-Service condition by sending specifically crafted packets to port 5010/tcp. This vulnerability is independent from CVE-2019-18290, CVE-2019-18291, CVE-2019-18292, CVE-2019-18294, CVE-2019-18298, CVE-2019-18299, CVE-2019-18300, CVE-2019-18301, CVE-2019-18302, CVE-2019-18303, CVE-2019-18304, CVE-2019-18305, and CVE-2019-18306. Please note that an attacker needs to have network access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    7.8
    High

    CVE-2019-18308

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a low privileged user account could gain root privileges by manipulating specific files in the local file system. This vulnerability is independent from CVE-2019-18309. Please note that an attacker needs to have local access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019
    7.8
    High

    CVE-2019-18309

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with local access to the MS3000 Server and a low privileged user account could gain root privileges by manipulating specific files in the local file system. This vulnerability is independent from CVE-2019-18308. Please note that an attacker needs to have local access to the MS3000 in order to exploit this vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

    Published: 12 Dec 2019