CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2019-8243

    Last Modified: 5 May 2025

    Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 14 Nov 2019
    4.3
    Medium

    CVE-2019-8242

    Last Modified: 5 May 2025

    Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 14 Nov 2019
    4.3
    Medium

    CVE-2019-8241

    Last Modified: 5 May 2025

    Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-8240

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-8239

    Last Modified: 21 Nov 2024

    Adobe Bridge CC versions 9.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to information disclosure.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-7962

    Last Modified: 21 Nov 2024

    Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-7960

    Last Modified: 21 Nov 2024

    Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.

    Published: 14 Nov 2019
    7.2
    High

    CVE-2019-18646

    Last Modified: 21 Nov 2024

    The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.

    Published: 14 Nov 2019
    7.2
    High

    CVE-2019-18647

    Last Modified: 21 Nov 2024

    The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.

    Published: 14 Nov 2019
    4.8
    Medium

    CVE-2019-18648

    Last Modified: 21 Nov 2024

    When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.

    Published: 14 Nov 2019
    4.8
    Medium

    CVE-2019-18649

    Last Modified: 21 Nov 2024

    When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2019-18895

    Last Modified: 21 Nov 2024

    Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.

    Published: 14 Nov 2019
    6.1
    Medium

    CVE-2019-18957

    Last Modified: 21 Nov 2024

    Microstrategy Library in MicroStrategy before 2019 before 11.1.3 has reflected XSS.

    Published: 14 Nov 2019
    8.8
    High

    CVE-2019-14869

    Last Modified: 21 Nov 2024

    A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-18949

    Last Modified: 21 Nov 2024

    SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.

    Published: 14 Nov 2019
    5.9
    Medium

    CVE-2019-16863

    Last Modified: 21 Nov 2024

    STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack because ECDSA scalar multiplication is mishandled, aka TPM-FAIL.

    Published: 14 Nov 2019
    9.8
    Critical

    CVE-2011-1930

    Last Modified: 21 Nov 2024

    In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2011-1588

    Last Modified: 21 Nov 2024

    Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.

    Published: 14 Nov 2019
    4.7
    Medium

    CVE-2011-1136

    Last Modified: 14 Sept 2026

    In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.

    Published: 14 Nov 2019
    7.8
    High

    CVE-2011-1070

    Last Modified: 21 Nov 2024

    v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences.

    Published: 14 Nov 2019
    4.8
    Medium

    CVE-2019-3640

    Last Modified: 21 Nov 2024

    Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP server via the ePO extension not using a secure connection when testing LDAP connectivity.

    Published: 14 Nov 2019
    7.5
    High

    CVE-2019-17185

    Last Modified: 21 Nov 2024

    In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.

    Published: 14 Nov 2019
    9.8
    Critical

    CVE-2019-18928

    Last Modified: 21 Nov 2024

    Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

    Published: 14 Nov 2019
    6.5
    Medium

    CVE-2014-8561

    Last Modified: 21 Nov 2024

    imagemagick 6.8.9.6 has remote DOS via infinite loop

    Published: 14 Nov 2019
    8.8
    High

    CVE-2019-10174

    Last Modified: 21 Nov 2024

    A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.

    Published: 14 Nov 2019
    9.8
    Critical

    CVE-2019-3663

    Last Modified: 21 Nov 2024

    Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD prior to 4.8. See the Security bulletin for further details

    Published: 13 Nov 2019
    6.5
    Medium

    CVE-2019-3662

    Last Modified: 21 Nov 2024

    Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed HTTP requests.

    Published: 13 Nov 2019
    8.1
    High

    CVE-2019-3661

    Last Modified: 21 Nov 2024

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database commands via carefully constructed time based payloads.

    Published: 13 Nov 2019
    5.3
    Medium

    CVE-2019-18954

    Last Modified: 21 Nov 2024

    Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and attributes in template/game-server/app/servers/connector/handler/entryHandler.js because certain internal attributes can be overwritten via a conflicting name. Hence, a malicious attacker can manipulate internal attributes by adding additional attributes to user input.

    Published: 13 Nov 2019
    8.4
    High

    CVE-2019-3660

    Last Modified: 21 Nov 2024

    Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed HTTP requests.

    Published: 13 Nov 2019
    6.1
    Medium

    CVE-2011-0544

    Last Modified: 21 Nov 2024

    phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

    Published: 13 Nov 2019
    5.3
    Medium

    CVE-2019-3650

    Last Modified: 21 Nov 2024

    Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET request extracting insecurely information stored in the database.

    Published: 13 Nov 2019
    8.8
    High

    CVE-2019-3651

    Last Modified: 21 Nov 2024

    Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using the atduser credentials, which were too permissive.

    Published: 13 Nov 2019
    9.8
    Critical

    CVE-2019-18952

    Last Modified: 21 Nov 2024

    SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

    Published: 13 Nov 2019
    7.5
    High

    CVE-2019-18951

    Last Modified: 21 Nov 2024

    SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.

    Published: 13 Nov 2019
    9.8
    Critical

    CVE-2019-5029

    Last Modified: 21 Nov 2024

    An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

    Published: 13 Nov 2019
    7.5
    High

    CVE-2010-5108

    Last Modified: 21 Nov 2024

    Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.

    Published: 13 Nov 2019
    5.3
    Medium

    CVE-2019-3649

    Last Modified: 21 Nov 2024

    Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.

    Published: 13 Nov 2019
    6.5
    Medium

    CVE-2019-3420

    Last Modified: 21 Nov 2024

    All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

    Published: 13 Nov 2019
    5.9
    Medium

    CVE-2019-13555

    Last Modified: 21 Nov 2024

    In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial number 21081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 21081 and prior, MELSEC-L Series L02/06/26CPU, L26CPU-BT: serial number 21101 and prior, L02/06/26CPU-P, L26CPU-PBT: serial number 21101 and prior, and L02/06/26CPU-CM, L26CPU-BT-CM: serial number 21101 and prior, a remote attacker can cause the FTP service to enter a denial-of-service condition dependent on the timing at which a remote attacker connects to the FTP server on the above CPU modules.

    Published: 13 Nov 2019
    9.8
    Critical

    CVE-2019-18240

    Last Modified: 21 Nov 2024

    In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.

    Published: 13 Nov 2019
    6.3
    Medium

    CVE-2019-0386

    Last Modified: 21 Nov 2024

    Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA Sales (corrected in S4CORE 1.0, 1.01, 1.02, 1.03, 1.04) does not execute the required authorization checks for an authenticated user, which can result in an escalation of privileges.

    Published: 13 Nov 2019
    7.1
    High

    CVE-2019-0396

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2, does not sufficiently validate an XML document accepted from an untrusted source. An attacker can craft a message that contains malicious elements that will not be correctly filtered by Web Intelligence HTML interface in some specific workflows.

    Published: 13 Nov 2019
    5.3
    Medium

    CVE-2019-0388

    Last Modified: 21 Nov 2024

    SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an attacker to manipulate content due to insufficient URL validation.

    Published: 13 Nov 2019
    4.3
    Medium

    CVE-2019-0391

    Last Modified: 21 Nov 2024

    Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.

    Published: 13 Nov 2019
    4.3
    Medium

    CVE-2019-0390

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users.

    Published: 13 Nov 2019
    4.3
    Medium

    CVE-2019-0393

    Last Modified: 21 Nov 2024

    An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an attacker to carry out targeted database queries that can read individual fields of historical inspection results.

    Published: 13 Nov 2019
    5.4
    Medium

    CVE-2019-0382

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publication related pages); corrected in version 4.2. Privileges are required in order to exploit this vulnerability.

    Published: 13 Nov 2019
    8.8
    High

    CVE-2019-0389

    Last Modified: 21 Nov 2024

    An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, 7.4, 7.5), may change privileges for all or some functions in Java Server, and enable users to execute functions, they are not allowed to execute otherwise.

    Published: 13 Nov 2019
    6.5
    Medium

    CVE-2019-0385

    Last Modified: 21 Nov 2024

    SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 13 Nov 2019