CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-11112

    Last Modified: 21 Nov 2024

    Memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver before 26.20.100.6813 (DCH) or 26.20.100.6812 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-0185

    Last Modified: 21 Nov 2024

    Insufficient access control in protected memory subsystem for SMM for 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor families; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 families; Intel(R) Xeon(R) E-2100 and E-2200 Processor families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.

    Published: 14 Nov 2019
    5.1
    Medium

    CVE-2019-0150

    Last Modified: 21 Nov 2024

    Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privileged user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-0149

    Last Modified: 21 Nov 2024

    Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-0148

    Last Modified: 21 Nov 2024

    Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-0147

    Last Modified: 21 Nov 2024

    Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-0146

    Last Modified: 21 Nov 2024

    Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    6.5
    Medium

    CVE-2019-0144

    Last Modified: 21 Nov 2024

    Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-0143

    Last Modified: 21 Nov 2024

    Unhandled exception in Kernel-mode drivers for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

    Published: 14 Nov 2019
    6.7
    Medium

    CVE-2019-0139

    Last Modified: 21 Nov 2024

    Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access.

    Published: 14 Nov 2019
    8.2
    High

    CVE-2019-0142

    Last Modified: 21 Nov 2024

    Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-0145

    Last Modified: 21 Nov 2024

    Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

    Published: 14 Nov 2019
    8.8
    High

    CVE-2019-0140

    Last Modified: 21 Nov 2024

    Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.

    Published: 14 Nov 2019
    9.8
    Critical

    CVE-2013-3072

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.

    Published: 14 Nov 2019
    9.8
    Critical

    CVE-2013-3073

    Last Modified: 21 Nov 2024

    A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

    Published: 14 Nov 2019
    8.2
    High

    CVE-2019-11137

    Last Modified: 21 Nov 2024

    Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

    Published: 14 Nov 2019
    8.1
    High

    CVE-2019-16110

    Last Modified: 21 Nov 2024

    The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data can be injected into the unencrypted UDP packet stream.

    Published: 14 Nov 2019
    6.7
    Medium

    CVE-2019-11136

    Last Modified: 21 Nov 2024

    Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-11153

    Last Modified: 21 Nov 2024

    Memory corruption issues in Intel(R) PROSet/Wireless WiFi Software extension DLL before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and a denial of service via local access.

    Published: 14 Nov 2019
    8.8
    High

    CVE-2019-11152

    Last Modified: 21 Nov 2024

    Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via adjacent access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-11151

    Last Modified: 21 Nov 2024

    Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-11156

    Last Modified: 21 Nov 2024

    Logic errors in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.

    Published: 14 Nov 2019
    7.1
    High

    CVE-2019-11155

    Last Modified: 21 Nov 2024

    Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.

    Published: 14 Nov 2019
    7.1
    High

    CVE-2019-11154

    Last Modified: 21 Nov 2024

    Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-14565

    Last Modified: 21 Nov 2024

    Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-14566

    Last Modified: 21 Nov 2024

    Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-14602

    Last Modified: 21 Nov 2024

    Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-11182

    Last Modified: 21 Nov 2024

    Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-11181

    Last Modified: 21 Nov 2024

    Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privilege via network access.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-11180

    Last Modified: 21 Nov 2024

    Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Nov 2019
    6.5
    Medium

    CVE-2019-11179

    Last Modified: 21 Nov 2024

    Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure via network access.

    Published: 14 Nov 2019
    8.1
    High

    CVE-2019-11178

    Last Modified: 21 Nov 2024

    Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/or denial of service via network access.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-11177

    Last Modified: 21 Nov 2024

    Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-11175

    Last Modified: 21 Nov 2024

    Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

    Published: 14 Nov 2019
    5.3
    Medium

    CVE-2019-11174

    Last Modified: 21 Nov 2024

    Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 14 Nov 2019
    7.1
    High

    CVE-2019-11173

    Last Modified: 21 Nov 2024

    Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via local access.

    Published: 14 Nov 2019
    5.3
    Medium

    CVE-2019-11172

    Last Modified: 21 Nov 2024

    Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

    Published: 14 Nov 2019
    9.8
    Critical

    CVE-2019-11171

    Last Modified: 21 Nov 2024

    Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-11170

    Last Modified: 21 Nov 2024

    Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access.

    Published: 14 Nov 2019
    9.1
    Critical

    CVE-2019-11168

    Last Modified: 21 Nov 2024

    Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

    Published: 14 Nov 2019
    4.3
    Medium

    CVE-2012-1161

    Last Modified: 21 Nov 2024

    Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

    Published: 14 Nov 2019
    7.5
    High

    CVE-2012-1170

    Last Modified: 21 Nov 2024

    Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15743

    Last Modified: 21 Nov 2024

    The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys contains a pre-installed app with a package name of com.sonymobile.android.maintenancetool.testmic app (versionCode=24, versionName=7.0) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record audio to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15475

    Last Modified: 21 Nov 2024

    The Xiaomi Mi A3 Android device with a build fingerprint of xiaomi/onc_eea/onc:9/PKQ1.181021.001/V10.2.8.0.PFLEUXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15474

    Last Modified: 21 Nov 2024

    The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15473

    Last Modified: 21 Nov 2024

    The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/jasmine/jasmine_sprout:9/PKQ1.180904.001/V10.0.2.0.PDIMIFJ:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15472

    Last Modified: 21 Nov 2024

    The Xiaomi Mi A2 Lite Android device with a build fingerprint of xiaomi/daisy/daisy_sprout:9/PKQ1.180917.001/V10.0.3.0.PDLMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a confused deputy attack. This capability can be accessed by any app co-located on the device. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15471

    Last Modified: 21 Nov 2024

    The Xiaomi Mi Mix 2S Android device with a build fingerprint of Xiaomi/polaris/polaris:8.0.0/OPR1.170623.032/V9.5.19.0.ODGMIFA:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15470

    Last Modified: 21 Nov 2024

    The Xiaomi Redmi Note 6 Pro Android device with a build fingerprint of xiaomi/tulip/tulip:8.1.0/OPM1.171019.011/V10.2.2.0.OEKMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019
    5.5
    Medium

    CVE-2019-15469

    Last Modified: 21 Nov 2024

    The Xiaomi Mi Pad 4 Android device with a build fingerprint of Xiaomi/clover/clover:8.1.0/OPM1.171019.019/V9.6.26.0.ODJCNFD:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=27, versionName=8.1.0) that allows other pre-installed apps to perform microphone audio recording via an accessible app component. This capability can be accessed by any pre-installed app on the device which can obtain signatureOrSystem permissions that are required by other other pre-installed apps that export their capabilities to other pre-installed app. This app allows a third-party app to use its open interface to record telephone calls to external storage.

    Published: 14 Nov 2019