CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2011-3586

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-3504. Reason: This candidate is a duplicate of CVE-2011-3504. Notes: All CVE users should reference CVE-2011-3504 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Nov 2019
    9.8
    Critical

    CVE-2019-16948

    Last Modified: 21 Nov 2024

    An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at WebServiceLocation=http://localhost:8085/UCWebServices/ with a range of ports to determine what is visible on the internal network (as opposed to what general web traffic would see on the product's host). The response from open ports is different than from closed ports. The product does not allow one to change the protocol: anything except http(s) will throw an error; however, it is the type of error that allows one to determine if a port is open or not.

    Published: 13 Nov 2019
    6.5
    Medium

    CVE-2019-5293

    Last Modified: 21 Nov 2024

    Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.

    Published: 13 Nov 2019
    7.5
    High

    CVE-2019-5294

    Last Modified: 21 Nov 2024

    There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corrupt or crafted message to the affected products. Due to a buffer read overflow error when parsing the message, successful exploit may cause some service to be abnormal.

    Published: 13 Nov 2019
    7.5
    High

    CVE-2019-5289

    Last Modified: 21 Nov 2024

    Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the active and standby communication channels. Successful exploit of this vulnerability could allow the attacker to crash the database on the standby node.

    Published: 13 Nov 2019
    6.5
    Medium

    CVE-2012-4385

    Last Modified: 21 Nov 2024

    letodms 3.3.6 has CSRF via change password

    Published: 13 Nov 2019
    9.8
    Critical

    CVE-2013-4654

    Last Modified: 21 Nov 2024

    Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..

    Published: 13 Nov 2019
    3.3
    Low

    CVE-2019-5292

    Last Modified: 21 Nov 2024

    Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module, an attacker with the access permission may exploit the vulnerability to obtain some information.

    Published: 13 Nov 2019
    6.1
    Medium

    CVE-2012-4384

    Last Modified: 21 Nov 2024

    letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar

    Published: 13 Nov 2019
    8.8
    High

    CVE-2019-18929

    Last Modified: 21 Nov 2024

    Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow.

    Published: 13 Nov 2019
    8.8
    High

    CVE-2019-18930

    Last Modified: 21 Nov 2024

    Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible to enter large-sized f_idx inputs.

    Published: 13 Nov 2019
    8.8
    High

    CVE-2019-18931

    Last Modified: 21 Nov 2024

    Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters.

    Published: 13 Nov 2019
    —
    Unknown

    CVE-2019-4159

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Nov 2019
    7.5
    High

    CVE-2013-4655

    Last Modified: 21 Nov 2024

    Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.

    Published: 13 Nov 2019
    8.8
    High

    CVE-2019-15948

    Last Modified: 21 Nov 2024

    Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote attackers to trigger a buffer overflow via a malformed Bluetooth Low Energy advertising packet, to cause a denial of service or potentially execute arbitrary code. This affects CC256xC-BT-SP 1.2, CC256xB-BT-SP 1.8, and WL18xx-BT-SP 4.4.

    Published: 13 Nov 2019
    7.8
    High

    CVE-2019-5288

    Last Modified: 21 Nov 2024

    P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Successful exploit could cause the program to break down or allow for arbitrary code execution.

    Published: 13 Nov 2019
    9.8
    Critical

    CVE-2013-4656

    Last Modified: 21 Nov 2024

    Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.

    Published: 13 Nov 2019
    7.8
    High

    CVE-2019-5287

    Last Modified: 21 Nov 2024

    P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Successful exploit could cause the program to break down or allow for arbitrary code execution.

    Published: 13 Nov 2019
    9
    Critical

    CVE-2019-18839

    Last Modified: 21 Nov 2024

    FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

    Published: 13 Nov 2019
    5.4
    Medium

    CVE-2019-17523

    Last Modified: 21 Nov 2024

    An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the FileName parameter to /FTPDiag.asp.

    Published: 13 Nov 2019
    5.4
    Medium

    CVE-2019-17524

    Last Modified: 21 Nov 2024

    An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via the "Connected Clients" field to /wlanAccess.asp. An intranet host can use a crafted hostname to exploit this.

    Published: 13 Nov 2019
    7.8
    High

    CVE-2019-5282

    Last Modified: 21 Nov 2024

    Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.

    Published: 13 Nov 2019
    5.5
    Medium

    CVE-2019-5279

    Last Modified: 21 Nov 2024

    Huawei smart phones Emily-L29C with Versions earlier than 9.1.0.311(C10E2R1P13T8), Versions earlier than 9.1.0.311(C461E2R1P11T8), Versions earlier than 9.1.0.316(C635E2R1P11T8), Versions earlier than 9.1.0.311(C185E2R1P12T8), Versions earlier than 9.1.0.311(C605E2R1P12T8), Versions earlier than 9.1.0.311(C636E7R1P13T8) have an information leakage vulnerability. An attacker tricks the user into installing a malicious application, which can copy specific files to the sdcard, resulting in information leakage.

    Published: 13 Nov 2019
    4.5
    Medium

    CVE-2019-3641

    Last Modified: 21 Nov 2024

    Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.

    Published: 13 Nov 2019
    6.1
    Medium

    CVE-2019-3648

    Last Modified: 21 Nov 2024

    A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.

    Published: 13 Nov 2019
    6.2
    Medium

    CVE-2019-5246

    Last Modified: 21 Nov 2024

    Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack. Successful exploit could cause DOS or malicious code execution.

    Published: 12 Nov 2019
    8.8
    High

    CVE-2019-5233

    Last Modified: 21 Nov 2024

    Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.

    Published: 12 Nov 2019
    4.6
    Medium

    CVE-2019-5231

    Last Modified: 21 Nov 2024

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.

    Published: 12 Nov 2019
    5.5
    Medium

    CVE-2019-5230

    Last Modified: 21 Nov 2024

    P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The system does not perform a properly validation of certain input models, an attacker could trick the user to install a malicious application then craft a malformed model, successful exploit could allow the attacker to get and tamper certain output data information.

    Published: 12 Nov 2019
    6.2
    Medium

    CVE-2019-5229

    Last Modified: 21 Nov 2024

    P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack, successful exploit could cause malicious code execution.

    Published: 12 Nov 2019
    2.4
    Low

    CVE-2019-5213

    Last Modified: 21 Nov 2024

    Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability. The system has a logic judge error under certain scenario. Successful exploit could allow the attacker to modify the alarm clock settings after a serious of uncommon operations without unlock the screen lock.

    Published: 12 Nov 2019
    7.8
    High

    CVE-2019-5228

    Last Modified: 21 Nov 2024

    Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly, when the function is called by multiple processes could cause out of bound write. An attacker tricks the user into installing a malicious application, successful exploit could cause malicious code execution.

    Published: 12 Nov 2019
    5.5
    Medium

    CVE-2010-4177

    Last Modified: 21 Nov 2024

    mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.

    Published: 12 Nov 2019
    8.8
    High

    CVE-2017-17224

    Last Modified: 21 Nov 2024

    Some Huawei smart phones with versions earlier than Harry-AL00C 9.1.0.206(C00E205R3P1) have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone abnormal.

    Published: 12 Nov 2019
    8.8
    High

    CVE-2010-3844

    Last Modified: 21 Nov 2024

    An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

    Published: 12 Nov 2019
    6.5
    Medium

    CVE-2011-1802

    Last Modified: 21 Nov 2024

    WebKit in Google Chrome before Blink M11 and M12 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption).

    Published: 12 Nov 2019
    5.5
    Medium

    CVE-2010-3440

    Last Modified: 21 Nov 2024

    babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.

    Published: 12 Nov 2019
    6.5
    Medium

    CVE-2011-1803

    Last Modified: 21 Nov 2024

    An issue exists in third_party/WebKit/Source/WebCore/svg/animation/SVGSMILElement.h in WebKit in Google Chrome before Blink M11 and M12 when trying to access a removed smil element.

    Published: 12 Nov 2019
    8.8
    High

    CVE-2010-3305

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.

    Published: 12 Nov 2019
    6.5
    Medium

    CVE-2011-2334

    Last Modified: 21 Nov 2024

    Use after free vulnerability exists in WebKit in Google Chrome before Blink M12 in RenderLayerwhen removing elements with reflections.

    Published: 12 Nov 2019
    6.5
    Medium

    CVE-2010-3299

    Last Modified: 21 Nov 2024

    The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

    Published: 12 Nov 2019
    7.5
    High

    CVE-2019-14365

    Last Modified: 21 Nov 2024

    The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).

    Published: 12 Nov 2019
    7.5
    High

    CVE-2019-14366

    Last Modified: 21 Nov 2024

    WP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).

    Published: 12 Nov 2019
    7.5
    High

    CVE-2019-14367

    Last Modified: 21 Nov 2024

    Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).

    Published: 12 Nov 2019
    9.8
    Critical

    CVE-2019-6188

    Last Modified: 21 Nov 2024

    The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.

    Published: 12 Nov 2019
    6.4
    Medium

    CVE-2019-6170

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.

    Published: 12 Nov 2019
    6.4
    Medium

    CVE-2019-6172

    Last Modified: 21 Nov 2024

    A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.

    Published: 12 Nov 2019
    5.5
    Medium

    CVE-2010-3292

    Last Modified: 21 Nov 2024

    The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishing whitelist) via dns/packet spoofing.

    Published: 12 Nov 2019
    4.7
    Medium

    CVE-2010-3095

    Last Modified: 21 Nov 2024

    mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313.

    Published: 12 Nov 2019
    —
    Unknown

    CVE-2019-16898

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16897. Reason: This candidate is a reservation duplicate of CVE-2019-16897. Notes: All CVE users should reference CVE-2019-16897 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Nov 2019