CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-8764

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8766

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8808

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8811

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8815

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8822

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8743

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8814

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8821

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8710

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8765

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8782

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8783

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8812

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    6.1
    Medium

    CVE-2019-8813

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8816

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8819

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8820

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    8.8
    High

    CVE-2019-8823

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 8 Nov 2019
    9.8
    Critical

    CVE-2008-7291

    Last Modified: 21 Nov 2024

    gri before 2.12.18 generates temporary files in an insecure way.

    Published: 7 Nov 2019
    7.5
    High

    CVE-2008-7272

    Last Modified: 21 Nov 2024

    FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2019-18835

    Last Modified: 21 Nov 2024

    Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

    Published: 7 Nov 2019
    4.3
    Medium

    CVE-2013-1811

    Last Modified: 21 Nov 2024

    An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".

    Published: 7 Nov 2019
    7.5
    High

    CVE-2013-1809

    Last Modified: 21 Nov 2024

    Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2007-6745

    Last Modified: 21 Nov 2024

    clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

    Published: 7 Nov 2019
    7.5
    High

    CVE-2013-1771

    Last Modified: 21 Nov 2024

    The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.

    Published: 7 Nov 2019
    7.5
    High

    CVE-2007-5743

    Last Modified: 21 Nov 2024

    viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2013-1751

    Last Modified: 21 Nov 2024

    TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.

    Published: 7 Nov 2019
    6.3
    Medium

    CVE-2013-1429

    Last Modified: 21 Nov 2024

    Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

    Published: 7 Nov 2019
    9.1
    Critical

    CVE-2007-3915

    Last Modified: 21 Nov 2024

    Mondo 2.24 has insecure handling of temporary files.

    Published: 7 Nov 2019
    5.5
    Medium

    CVE-2007-3732

    Last Modified: 21 Nov 2024

    In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments are set properly. The kernel's %fs needs to be restored before the call in TRACE_IRQS_ON and before enabling interrupts, so that "current" references work. Without this, "current" used in the window between iret_exc and the middle of error_code where %fs is reset, would crash.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2019-18818

    Last Modified: 21 Nov 2024

    strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/strapi-plugin-users-permissions/controllers/Auth.js.

    Published: 7 Nov 2019
    6.1
    Medium

    CVE-2018-18674

    Last Modified: 21 Nov 2024

    GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter.

    Published: 7 Nov 2019
    6.1
    Medium

    CVE-2013-1426

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.

    Published: 7 Nov 2019
    5.5
    Medium

    CVE-2019-18819

    Last Modified: 21 Nov 2024

    Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7.

    Published: 7 Nov 2019
    5.5
    Medium

    CVE-2019-18821

    Last Modified: 21 Nov 2024

    Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfile::BuildGradientColorsTable+0x0000000000000053.

    Published: 7 Nov 2019
    5.5
    Medium

    CVE-2019-18820

    Last Modified: 21 Nov 2024

    Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

    Published: 7 Nov 2019
    5.5
    Medium

    CVE-2013-1425

    Last Modified: 21 Nov 2024

    ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2010-2476

    Last Modified: 21 Nov 2024

    syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot.

    Published: 7 Nov 2019
    7.5
    High

    CVE-2010-2450

    Last Modified: 21 Nov 2024

    The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

    Published: 7 Nov 2019
    6.5
    Medium

    CVE-2010-2449

    Last Modified: 21 Nov 2024

    Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2010-2447

    Last Modified: 21 Nov 2024

    gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

    Published: 7 Nov 2019
    6.2
    Medium

    CVE-2019-3422

    Last Modified: 21 Nov 2024

    The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October 2019. Through the analysis of related product team, the information disclosure vulnerability is confirmed. The MF910S product's one-click upgrade tool can obtain the Telnet remote login password in the reverse way. If Telnet is opened, the attacker can remotely log in to the device through the cracked password, resulting in information leakage. The MF910S was end of service on October 23, 2019, ZTE recommends users to choose new products for the purpose of better security.

    Published: 7 Nov 2019
    8.8
    High

    CVE-2019-3465

    Last Modified: 21 Nov 2024

    Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.

    Published: 7 Nov 2019
    9.8
    Critical

    CVE-2019-11996

    Last Modified: 21 Nov 2024

    Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations. The vulnerabilities could be exploited by an attacker to gain elevated privileges on the array. The following NimbleOS versions, and all subsequent releases, contain a software fix for this vulnerability: 3.9.2.0, 4.5.5.0, 5.0.8.0 and 5.1.3.0.

    Published: 7 Nov 2019
    6.5
    Medium

    CVE-2010-2473

    Last Modified: 21 Nov 2024

    Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user with an open session that was blocked could maintain their session on the Drupal site despite being blocked.

    Published: 7 Nov 2019
    4.3
    Medium

    CVE-2019-3764

    Last Modified: 21 Nov 2024

    Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an improper authorization vulnerability. A remote authenticated malicious iDRAC user with low privileges may potentially exploit this vulnerability to obtain sensitive information such as password hashes.

    Published: 7 Nov 2019
    4.8
    Medium

    CVE-2010-2472

    Last Modified: 21 Nov 2024

    Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

    Published: 7 Nov 2019
    6.1
    Medium

    CVE-2010-2250

    Last Modified: 21 Nov 2024

    Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

    Published: 7 Nov 2019
    6.5
    Medium

    CVE-2011-2336

    Last Modified: 21 Nov 2024

    An issue exists in WebKit in Google Chrome before Blink M12. when clearing lists in AnimationControllerPrivate that signal when a hardware animation starts.

    Published: 7 Nov 2019