CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-13736

    Last Modified: 21 Nov 2024

    Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13737

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13738

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13739

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13741

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13745

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13747

    Last Modified: 21 Nov 2024

    Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13750

    Last Modified: 21 Nov 2024

    Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13754

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13755

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13756

    Last Modified: 21 Nov 2024

    Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 10 Dec 2019
    3.3
    Low

    CVE-2019-13762

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-1387

    Last Modified: 4 Nov 2025

    An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. Recursive clones are currently affected by a vulnerability that is caused by too-lax validation of submodule names, allowing very targeted attacks via remote code execution in recursive clones.

    Published: 10 Dec 2019
    6.1
    Medium

    CVE-2016-1000107

    Last Modified: 21 Nov 2024

    inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-1350

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

    Published: 10 Dec 2019
    7.5
    High

    CVE-2019-1351

    Last Modified: 21 Nov 2024

    A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'.

    Published: 10 Dec 2019
    —
    Unknown

    CVE-2020-2521

    Last Modified: 12 Jun 2026

    This candidate was issued in error.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-1352

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13726

    Last Modified: 21 Nov 2024

    Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13730

    Last Modified: 21 Nov 2024

    Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13732

    Last Modified: 21 Nov 2024

    Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    8.8
    High

    CVE-2019-13734

    Last Modified: 21 Nov 2024

    Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13744

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13746

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13749

    Last Modified: 21 Nov 2024

    Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13751

    Last Modified: 21 Nov 2024

    Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 10 Dec 2019
    6.5
    Medium

    CVE-2019-13753

    Last Modified: 21 Nov 2024

    Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 10 Dec 2019
    4.3
    Medium

    CVE-2019-13759

    Last Modified: 21 Nov 2024

    Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 10 Dec 2019
    9.8
    Critical

    CVE-2019-4621

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.

    Published: 9 Dec 2019
    8.8
    High

    CVE-2019-4612

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks. IBM X-Force ID: 168523.

    Published: 9 Dec 2019
    5.4
    Medium

    CVE-2019-4611

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 168519.

    Published: 9 Dec 2019
    5.4
    Medium

    CVE-2019-4428

    Last Modified: 21 Nov 2024

    IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 162807.

    Published: 9 Dec 2019
    4.3
    Medium

    CVE-2013-0342

    Last Modified: 21 Nov 2024

    The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.

    Published: 9 Dec 2019
    9.8
    Critical

    CVE-2019-19230

    Last Modified: 21 Nov 2024

    An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.

    Published: 9 Dec 2019
    7.8
    High

    CVE-2015-7892

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in Samsung S6 Edge, allows local users to have unspecified impact via a large data.buf_out.num_planes value in an ioctl call.

    Published: 9 Dec 2019
    8.8
    High

    CVE-2015-3424

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.

    Published: 9 Dec 2019
    6.1
    Medium

    CVE-2015-3425

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.

    Published: 9 Dec 2019
    9.8
    Critical

    CVE-2019-18190

    Last Modified: 21 Nov 2024

    Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.

    Published: 9 Dec 2019
    7.5
    High

    CVE-2015-0841

    Last Modified: 21 Nov 2024

    Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.

    Published: 9 Dec 2019
    6.5
    Medium

    CVE-2019-18380

    Last Modified: 21 Nov 2024

    Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue that could potentially allow a threat actor to create or modify application user accounts without proper authentication.

    Published: 9 Dec 2019
    —
    Unknown

    CVE-2019-12424

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Dec 2019
    —
    Unknown

    CVE-2018-17185

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Dec 2019
    4.8
    Medium

    CVE-2019-19682

    Last Modified: 21 Nov 2024

    nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Controllers\NewsController.cs and \Presentation\Nop.Web\Areas\Admin\Controllers\BlogController.cs via Body or Full to Admin/News/NewsItemEdit/[id] Admin/Blog/BlogPostEdit/[id]. NOTE: the vendor reportedly considers this a "feature" because the affected components are an HTML content editor.

    Published: 9 Dec 2019
    8.8
    High

    CVE-2019-19684

    Last Modified: 21 Nov 2024

    nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginController.cs via Admin/FacebookAuthentication/Configure because it is possible to upload a crafted Facebook Auth plugin.

    Published: 9 Dec 2019
    8.8
    High

    CVE-2019-19685

    Last Modified: 21 Nov 2024

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

    Published: 9 Dec 2019
    9.1
    Critical

    CVE-2019-19683

    Last Modified: 21 Nov 2024

    RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.

    Published: 9 Dec 2019
    7.5
    High

    CVE-2019-14251

    Last Modified: 21 Nov 2024

    An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

    Published: 9 Dec 2019
    5.4
    Medium

    CVE-2019-19678

    Last Modified: 21 Nov 2024

    In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic field entry point via the Generic Test Definition field of a new Generic Test issue.

    Published: 9 Dec 2019
    5.4
    Medium

    CVE-2019-19679

    Last Modified: 21 Nov 2024

    In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condition Summary entry point via the summary field of a Create Pre-Condition action for a new Test Issue.

    Published: 9 Dec 2019
    5.5
    Medium

    CVE-2020-10720

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's implementation of GRO in versions before 5.2. This flaw allows an attacker with local access to crash the system.

    Published: 9 Dec 2019