CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2011-4632

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the tcemain flash message.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2011-4631

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the system extension recycler.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2011-4630

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the browse_links wizard.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2011-4629

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the admin panel.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2011-4628

    Last Modified: 21 Nov 2024

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to bypass authentication mechanisms in the backend through a crafted request.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2010-2446

    Last Modified: 21 Nov 2024

    Rbot Reaction plugin allows command execution

    Published: 6 Nov 2019
    6.5
    Medium

    CVE-2011-4627

    Last Modified: 21 Nov 2024

    TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows Information Disclosure on the backend.

    Published: 6 Nov 2019
    6.1
    Medium

    CVE-2011-4626

    Last Modified: 21 Nov 2024

    Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the "JSwindow" property of the typolink function.

    Published: 6 Nov 2019
    8.8
    High

    CVE-2019-18800

    Last Modified: 21 Nov 2024

    Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on port 4244 from the victim's device contains cleartext information such as the device model and OS version, IMSI, and 20 bytes of udid in a binary format, which is located at offset 0x14 of this packet. Then, the attacker installs Viber on his device, initiates the registration process for any phone number, but doesn't enter a pin from SMS. Instead, he closes Viber. Next, the attacker rewrites his udid with the victim's udid, modifying the viber_udid file, which is located in the Viber preferences folder. (The udid is stored in a hexadecimal format.) Finally, the attacker starts Viber again and enters the pin from SMS.

    Published: 6 Nov 2019
    6.1
    Medium

    CVE-2017-18639

    Last Modified: 21 Nov 2024

    Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : List Title, /Content/Documents/LibraryDocuments/incident-request-attachments Parameter : Document Title, /Content/Images/LibraryImages/newsimages Parameter : Image Title, /Content/links Parameter : Link Title, /Content/links Parameter : Link Title, or /Content/Videos/LibraryVideos/default-video-library Parameter : Video Title.

    Published: 6 Nov 2019
    5.9
    Medium

    CVE-2015-7276

    Last Modified: 21 Nov 2024

    Technicolor C2000T and C2100T uses hard-coded cryptographic keys.

    Published: 6 Nov 2019
    —
    Unknown

    CVE-2018-20320

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11032. Reason: This candidate is a reservation duplicate of CVE-2019-11032. Notes: All CVE users should reference CVE-2019-11032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2019-13081

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.php service desk ticket functionality) that allows an authenticated user to execute arbitrary JavaScript in a service desk user's browser.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2019-13080

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated user to execute arbitrary JavaScript in an administrator's browser.

    Published: 6 Nov 2019
    7.5
    High

    CVE-2011-4625

    Last Modified: 21 Nov 2024

    simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

    Published: 6 Nov 2019
    8.8
    High

    CVE-2019-13079

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /adminui/history_log.php. The affected parameter is TYPE_NAME.

    Published: 6 Nov 2019
    8.8
    High

    CVE-2019-13078

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /common/user_profile.php. The affected parameter is sort_column.

    Published: 6 Nov 2019
    6.1
    Medium

    CVE-2019-13077

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows an attacker to create a malicious link in order to attack authenticated users.

    Published: 6 Nov 2019
    8.8
    High

    CVE-2019-13076

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /userui/ticket_list.php, and affected parameters are order[0][column] and order[0][dir].

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2019-12918

    Last Modified: 21 Nov 2024

    Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].

    Published: 6 Nov 2019
    6.1
    Medium

    CVE-2019-12917

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2016-4401

    Last Modified: 21 Nov 2024

    Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.

    Published: 6 Nov 2019
    —
    Unknown

    CVE-2007-2841

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-3947. Reason: This candidate is a reservation duplicate of CVE-2007-3947. Notes: All CVE users should reference CVE-2007-3947 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2007-0899

    Last Modified: 21 Nov 2024

    There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

    Published: 6 Nov 2019
    8.1
    High

    CVE-2006-4245

    Last Modified: 21 Nov 2024

    archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2006-4243

    Last Modified: 21 Nov 2024

    linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2006-3100

    Last Modified: 21 Nov 2024

    termpkg 3.3 suffers from buffer overflow.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2019-18784

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2006-0062

    Last Modified: 21 Nov 2024

    xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2006-0061

    Last Modified: 21 Nov 2024

    xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.

    Published: 6 Nov 2019
    8.8
    High

    CVE-2019-18650

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.

    Published: 6 Nov 2019
    5.3
    Medium

    CVE-2019-18674

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a path disclosure.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2019-8132

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can craft malicious payload in the template Name field for Email template in the "Design Configuration" dashboard.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2019-8145

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code into the attribute set name when listing the products.

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2019-8158

    Last Modified: 21 Nov 2024

    An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An attacker can craft a GET request to page cache block rendering module that gets passed to XML data processing engine without validation. The crafted key/value GET request data allows an attacker to limited access to underlying XML data.

    Published: 6 Nov 2019
    5.4
    Medium

    CVE-2019-8157

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can manipulate downloadable link and cause an invocation of error handling that acceses user input without sanitization.

    Published: 6 Nov 2019
    7.2
    High

    CVE-2019-8156

    Last Modified: 21 Nov 2024

    A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with admin privileges to modify store configurations can manipulate the connector api endpoint to enable remote code execution.

    Published: 6 Nov 2019
    8.8
    High

    CVE-2019-8159

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbitrary file deletion and OS command injection.

    Published: 6 Nov 2019
    4.8
    Medium

    CVE-2019-8227

    Last Modified: 21 Nov 2024

    In Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code via import / export functionality when creating profile action XML.

    Published: 6 Nov 2019
    7.1
    High

    CVE-2020-27792

    Last Modified: 20 Nov 2025

    A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

    Published: 6 Nov 2019
    7.5
    High

    CVE-2019-19203

    Last Modified: 21 Nov 2024

    An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read.

    Published: 6 Nov 2019
    7.5
    High

    CVE-2019-19204

    Last Modified: 21 Nov 2024

    An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

    Published: 6 Nov 2019
    7.8
    High

    CVE-2019-19807

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.

    Published: 6 Nov 2019
    6.5
    Medium

    CVE-2019-25014

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application).

    Published: 6 Nov 2019
    6.5
    Medium

    CVE-2019-12406

    Last Modified: 21 Nov 2024

    Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachments is enforced. This is configurable via the message property "attachment-max-count".

    Published: 6 Nov 2019
    9.8
    Critical

    CVE-2019-12419

    Last Modified: 21 Nov 2024

    Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to somehow steal an authorization code issued to another client, then they could exploit this vulnerability to obtain an access token for the other client.

    Published: 6 Nov 2019
    4.8
    Medium

    CVE-2019-8228

    Last Modified: 21 Nov 2024

    in Magento prior to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with limited administrative privileges can inject arbitrary JavaScript code into transactional email page when creating a new email template or editing existing email template.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8229

    Last Modified: 21 Nov 2024

    In Magento prior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit product attributes can execute arbitrary code through crafted layout updates.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8230

    Last Modified: 21 Nov 2024

    In Magentoprior to 1.9.4.3, and Magento prior to 1.14.4.3, an authenticated user with administrative privileges to edit configuration settings can execute arbitrary code through a crafted support/output path.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-8231

    Last Modified: 21 Nov 2024

    In Magento to 1.9.4.3 and Magento prior to 1.14.4.3, an authenticated user with administrative privileges for editing attribute sets can execute arbitrary code through custom layout modification.

    Published: 5 Nov 2019