CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-19227

    Last Modified: 21 Nov 2024

    In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c, as demonstrated by unregister_snap_client, aka CID-9804501fa122.

    Published: 22 Nov 2019
    7.8
    High

    CVE-2019-18675

    Last Modified: 21 Nov 2024

    The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allows local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation.

    Published: 22 Nov 2019
    9.8
    Critical

    CVE-2019-14901

    Last Modified: 21 Nov 2024

    A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.

    Published: 22 Nov 2019
    7.5
    High

    CVE-2019-19244

    Last Modified: 21 Nov 2024

    sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.

    Published: 22 Nov 2019
    8.8
    High

    CVE-2012-2079

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal.

    Published: 21 Nov 2019
    4.8
    Medium

    CVE-2012-2078

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal.

    Published: 21 Nov 2019
    4.8
    Medium

    CVE-2012-1637

    Last Modified: 24 Sept 2026

    Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-18933

    Last Modified: 21 Nov 2024

    In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user's account.

    Published: 21 Nov 2019
    7
    High

    CVE-2014-5255

    Last Modified: 21 Nov 2024

    xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.

    Published: 21 Nov 2019
    4.7
    Medium

    CVE-2014-5254

    Last Modified: 21 Nov 2024

    xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-18889

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2019-18888

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).

    Published: 21 Nov 2019
    8.1
    High

    CVE-2019-18887

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-11325

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2014-2904

    Last Modified: 21 Nov 2024

    wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2014-2902

    Last Modified: 21 Nov 2024

    wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2014-2901

    Last Modified: 21 Nov 2024

    wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

    Published: 21 Nov 2019
    6.1
    Medium

    CVE-2012-1001

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.

    Published: 21 Nov 2019
    8.8
    High

    CVE-2014-8356

    Last Modified: 21 Nov 2024

    The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.

    Published: 21 Nov 2019
    8.8
    High

    CVE-2015-3140

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567

    Published: 21 Nov 2019
    8.8
    High

    CVE-2019-19207

    Last Modified: 21 Nov 2024

    rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.

    Published: 21 Nov 2019
    8.8
    High

    CVE-2019-19202

    Last Modified: 21 Nov 2024

    In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.

    Published: 21 Nov 2019
    6.1
    Medium

    CVE-2015-2793

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2013-3311

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request.

    Published: 21 Nov 2019
    8.8
    High

    CVE-2013-3312

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2013-3313

    Last Modified: 21 Nov 2024

    The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal vulnerability in CVE-2013-3311.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2013-3314

    Last Modified: 21 Nov 2024

    The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2019-5637

    Last Modified: 21 Nov 2024

    When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

    Published: 21 Nov 2019
    5.3
    Medium

    CVE-2019-5636

    Last Modified: 21 Nov 2024

    When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. This issue affects TwinCAT 2 version 2304 (and prior) and TwinCAT 3.1 version 4204.0 (and prior).

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-19197

    Last Modified: 21 Nov 2024

    IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402401 using METHOD_NEITHER results in a read primitive.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2019-16758

    Last Modified: 21 Nov 2024

    In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-18349

    Last Modified: 21 Nov 2024

    HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-19033

    Last Modified: 21 Nov 2024

    Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-19006

    Last Modified: 4 Feb 2026

    Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-15511

    Last Modified: 21 Nov 2024

    An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected.

    Published: 21 Nov 2019
    6.5
    Medium

    CVE-2019-18890

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

    Published: 21 Nov 2019
    5.3
    Medium

    CVE-2019-18886

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-16406

    Last Modified: 21 Nov 2024

    Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.

    Published: 21 Nov 2019
    7.2
    High

    CVE-2019-16405

    Last Modified: 21 Nov 2024

    Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. CVE-2019-16405 and CVE-2019-17501 are similar to one another and may be the same.

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-19191

    Last Modified: 21 Nov 2024

    Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-5072

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS2 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-5071

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS1 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability.

    Published: 21 Nov 2019
    7.5
    High

    CVE-2019-10767

    Last Modified: 21 Nov 2024

    An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the authentication is enabled (by default isn't enabled).

    Published: 21 Nov 2019
    8.8
    High

    CVE-2019-5087

    Last Modified: 21 Nov 2024

    An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to corrupt memory and eventually execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

    Published: 21 Nov 2019
    8.8
    High

    CVE-2019-5086

    Last Modified: 21 Nov 2024

    An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.

    Published: 21 Nov 2019
    7.2
    High

    CVE-2019-17272

    Last Modified: 21 Nov 2024

    All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2019-5509

    Last Modified: 21 Nov 2024

    ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.

    Published: 21 Nov 2019
    9.8
    Critical

    CVE-2018-8879

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id.

    Published: 21 Nov 2019
    6.5
    Medium

    CVE-2019-6693

    Last Modified: 24 Oct 2025

    Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set).

    Published: 21 Nov 2019
    7.8
    High

    CVE-2019-17650

    Last Modified: 21 Nov 2024

    An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security check.

    Published: 21 Nov 2019