CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-1465

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467.

    Published: 10 Dec 2019
    5.5
    Medium

    CVE-2019-1464

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-1466

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467.

    Published: 10 Dec 2019
    7.8
    High

    CVE-2019-1462

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'.

    Published: 10 Dec 2019
    5.5
    Medium

    CVE-2019-1463

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400.

    Published: 10 Dec 2019
    7.8
    High

    CVE-2019-1458

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-1461

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'.

    Published: 10 Dec 2019
    7.5
    High

    CVE-2019-1453

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

    Published: 10 Dec 2019
    6.1
    Medium

    CVE-2019-1332

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.

    Published: 10 Dec 2019
    5.5
    Medium

    CVE-2019-1400

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1463.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2019-17270

    Last Modified: 21 Nov 2024

    Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-5843

    Last Modified: 21 Nov 2024

    Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-5841

    Last Modified: 21 Nov 2024

    Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13672

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page on iOS.

    Published: 10 Dec 2019
    6.1
    Medium

    CVE-2019-19703

    Last Modified: 21 Nov 2024

    In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.

    Published: 10 Dec 2019
    7.5
    High

    CVE-2019-19702

    Last Modified: 21 Nov 2024

    The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this to perform a denial of service against the DMARC reporting functionality, such as by referencing the /dev/random file within XML documents that are emailed to the address in the rua field of the DMARC records of a domain.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2012-1577

    Last Modified: 21 Nov 2024

    lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.

    Published: 10 Dec 2019
    4.4
    Medium

    CVE-2019-6192

    Last Modified: 21 Nov 2024

    A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.

    Published: 10 Dec 2019
    7.5
    High

    CVE-2019-6183

    Last Modified: 21 Nov 2024

    A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause systems to experience a blue screen error. Lenovo Energy Management is a client utility. Lenovo XClarity Energy Manager is not affected.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2019-18801

    Last Modified: 21 Nov 2024

    An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outside of the request buffers when the upstream is HTTP/1. This may be used to corrupt nearby heap contents (leading to a query-of-death scenario) or may be used to bypass Envoy's access control mechanisms such as path based routing. An attacker can also modify requests from other users that happen to be proximal temporally and spatially.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2019-18802

    Last Modified: 21 Nov 2024

    An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespace after the header content. Envoy will treat "header-value " as a different string from "header-value" so for example with the Host header "example.com " one could bypass "example.com" matchers.

    Published: 10 Dec 2019
    7.5
    High

    CVE-2019-18838

    Last Modified: 21 Nov 2024

    An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer dereference, resulting in abnormal termination of the Envoy process.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2013-1689

    Last Modified: 21 Nov 2024

    Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

    Published: 10 Dec 2019
    5.4
    Medium

    CVE-2019-4663

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171245.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2019-4521

    Last Modified: 21 Nov 2024

    Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 165179.

    Published: 10 Dec 2019
    9.1
    Critical

    CVE-2019-4244

    Last Modified: 21 Nov 2024

    IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestricted control over Zookeeper installations due to missing authentication. IBM X-Force ID: 159518.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-4095

    Last Modified: 21 Nov 2024

    IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158015.

    Published: 10 Dec 2019
    6.1
    Medium

    CVE-2016-1000108

    Last Modified: 21 Nov 2024

    yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

    Published: 10 Dec 2019
    7.1
    High

    CVE-2013-2183

    Last Modified: 21 Nov 2024

    Monkey HTTP Daemon has local security bypass

    Published: 10 Dec 2019
    5.3
    Medium

    CVE-2019-19251

    Last Modified: 21 Nov 2024

    The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by default, and cleartext requests are made as soon as the app starts.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2013-2159

    Last Modified: 21 Nov 2024

    Monkey HTTP Daemon: broken user name authentication

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-19698

    Last Modified: 21 Nov 2024

    marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-11049

    Last Modified: 17 Aug 2026

    In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13764

    Last Modified: 21 Nov 2024

    Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13761

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 10 Dec 2019
    5.3
    Medium

    CVE-2019-14861

    Last Modified: 21 Nov 2024

    All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer.

    Published: 10 Dec 2019
    5.5
    Medium

    CVE-2013-4184

    Last Modified: 21 Nov 2024

    Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

    Published: 10 Dec 2019
    7.5
    High

    CVE-2019-20907

    Last Modified: 21 Nov 2024

    In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

    Published: 10 Dec 2019
    3.3
    Low

    CVE-2019-1348

    Last Modified: 21 Nov 2024

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-1349

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2019-1353

    Last Modified: 21 Nov 2024

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while accessing a working directory on a regular Windows drive, none of the NTFS protections were active.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13725

    Last Modified: 21 Nov 2024

    Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13740

    Last Modified: 21 Nov 2024

    Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13742

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13743

    Last Modified: 21 Nov 2024

    Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13748

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13752

    Last Modified: 21 Nov 2024

    Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13757

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13758

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13763

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

    Published: 10 Dec 2019