CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2012-6070

    Last Modified: 21 Nov 2024

    Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks.

    Published: 19 Nov 2019
    5.5
    Medium

    CVE-2012-0843

    Last Modified: 21 Nov 2024

    uzbl: Information disclosure via world-readable cookies storage file

    Published: 19 Nov 2019
    9.8
    Critical

    CVE-2012-0824

    Last Modified: 21 Nov 2024

    gnusound 0.7.5 has format string issue

    Published: 19 Nov 2019
    7.5
    High

    CVE-2011-4919

    Last Modified: 21 Nov 2024

    mpack 1.6 has information disclosure via eavesdropping on mails sent by other users

    Published: 19 Nov 2019
    4.8
    Medium

    CVE-2011-4968

    Last Modified: 21 Nov 2024

    nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

    Published: 19 Nov 2019
    7.8
    High

    CVE-2014-5439

    Last Modified: 21 Nov 2024

    Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code.

    Published: 19 Nov 2019
    5.5
    Medium

    CVE-2012-0842

    Last Modified: 21 Nov 2024

    surf: cookie jar has read access from other local user

    Published: 19 Nov 2019
    9.8
    Critical

    CVE-2016-1000006

    Last Modified: 21 Nov 2024

    hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.

    Published: 19 Nov 2019
    7.3
    High

    CVE-2019-16861

    Last Modified: 21 Nov 2024

    Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local server could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute arbitrary code at an elevated privilege on the local server.

    Published: 19 Nov 2019
    7.3
    High

    CVE-2019-16860

    Last Modified: 21 Nov 2024

    Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attacker on the local machine could create or modify a dynamic-link library (DLL). The Code42 service could then load it at runtime, and potentially execute arbitrary code at an elevated privilege on the local machine.

    Published: 19 Nov 2019
    3.3
    Low

    CVE-2019-19126

    Last Modified: 21 Nov 2024

    On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.

    Published: 19 Nov 2019
    7.4
    High

    CVE-2019-10764

    Last Modified: 21 Nov 2024

    In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key.

    Published: 18 Nov 2019
    7.8
    High

    CVE-2008-7273

    Last Modified: 21 Nov 2024

    A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2012-4441

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

    Published: 18 Nov 2019
    8.8
    High

    CVE-2019-19117

    Last Modified: 21 Nov 2024

    /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2012-4440

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

    Published: 18 Nov 2019
    5.6
    Medium

    CVE-2019-18373

    Last Modified: 21 Nov 2024

    Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking other apps on the device, thereby allowing the individual to gain access.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2019-15054

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbitrary JavaScript in a privileged context via a crafted HTML mail message. This vulnerability is distinct from CVE-2015-4657.

    Published: 18 Nov 2019
    —
    Unknown

    CVE-2019-12403

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Nov 2019
    6.5
    Medium

    CVE-2019-17085

    Last Modified: 21 Nov 2024

    XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerability could be exploited to do an XXE attack on Operations Agent.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2019-10070

    Last Modified: 21 Nov 2024

    Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality

    Published: 18 Nov 2019
    7.8
    High

    CVE-2019-18215

    Last Modified: 21 Nov 2024

    An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product directory. This DLL is then loaded into a high-privileged service before the binary signature validation logic is loaded, and might bypass some of the self-defense mechanisms.

    Published: 18 Nov 2019
    6.5
    Medium

    CVE-2019-10763

    Last Modified: 21 Nov 2024

    pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) can achieve a SQL injection that can lead in data leakage. The vulnerability can be exploited via 'id', 'storeId', 'pageSize' and 'tables' parameters, using a payload for trigger a time based or error based sql injection.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2019-12311

    Last Modified: 21 Nov 2024

    Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a script could be uploaded to the server. When a victim tries to download a CISO Report template, the script is loaded.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2019-12299

    Last Modified: 21 Nov 2024

    Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section.

    Published: 18 Nov 2019
    8.2
    High

    CVE-2019-3424

    Last Modified: 21 Nov 2024

    authentication issues vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can automatically obtain access to web services from the authorized browser of the same computer and perform operations.

    Published: 18 Nov 2019
    5.3
    Medium

    CVE-2019-3423

    Last Modified: 21 Nov 2024

    permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2019-12271

    Last Modified: 21 Nov 2024

    Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2018-20687

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Published: 18 Nov 2019
    4
    Medium

    CVE-2019-5102

    Last Modified: 21 Nov 2024

    An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.

    Published: 18 Nov 2019
    4
    Medium

    CVE-2019-5101

    Last Modified: 21 Nov 2024

    An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request.An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data sent by the client during the first request. After an SSL connection is initialized via _ustream_ssl_init, and after any data (e.g. the client's HTTP request) is written to the stream using ustream_printf, the code eventually enters the function _ustream_ssl_poll, which is used to dispatch the read/write events

    Published: 18 Nov 2019
    6.7
    Medium

    CVE-2019-5688

    Last Modified: 21 Nov 2024

    NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2011-5331

    Last Modified: 21 Nov 2024

    Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2011-5330

    Last Modified: 21 Nov 2024

    Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2019-19113

    Last Modified: 21 Nov 2024

    main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.

    Published: 18 Nov 2019
    6.5
    Medium

    CVE-2018-21031

    Last Modified: 21 Nov 2024

    Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further research indicated that Tautulli is the correct affected product.

    Published: 18 Nov 2019
    5.4
    Medium

    CVE-2019-19085

    Last Modified: 21 Nov 2024

    A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.

    Published: 18 Nov 2019
    4.3
    Medium

    CVE-2019-19084

    Last Modified: 21 Nov 2024

    In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2018-13257

    Last Modified: 21 Nov 2024

    The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.

    Published: 18 Nov 2019
    7.8
    High

    CVE-2019-14467

    Last Modified: 21 Nov 2024

    The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.

    Published: 18 Nov 2019
    9.1
    Critical

    CVE-2019-17058

    Last Modified: 21 Nov 2024

    Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by an Administrator who uploads a crafted upload.dat file.

    Published: 18 Nov 2019
    6.1
    Medium

    CVE-2019-17057

    Last Modified: 21 Nov 2024

    Footy Tipping Software AFL Web Edition 2019 allows XSS.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19074

    Last Modified: 21 Nov 2024

    A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.

    Published: 18 Nov 2019
    4
    Medium

    CVE-2019-19073

    Last Modified: 21 Nov 2024

    Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, and the htc_connect_service() function, aka CID-853acf7caf10.

    Published: 18 Nov 2019
    4.4
    Medium

    CVE-2019-19072

    Last Modified: 21 Nov 2024

    A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19071

    Last Modified: 21 Nov 2024

    A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19070

    Last Modified: 21 Nov 2024

    A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() failures, aka CID-d3b0ffa1d75d. NOTE: third parties dispute the relevance of this because the system must have already been out of memory before the probe began

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19069

    Last Modified: 21 Nov 2024

    A memory leak in the fastrpc_dma_buf_attach() function in drivers/misc/fastrpc.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering dma_get_sgtable() failures, aka CID-fc739a058d99.

    Published: 18 Nov 2019
    4.6
    Medium

    CVE-2019-19068

    Last Modified: 21 Nov 2024

    A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.

    Published: 18 Nov 2019
    4.4
    Medium

    CVE-2019-19067

    Last Modified: 21 Nov 2024

    Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading

    Published: 18 Nov 2019