CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2019-8091

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user with privileges to access product attributes can leverage layout updates to trigger remote code execution.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-8093

    Last Modified: 21 Nov 2024

    An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can leverage file upload controller for downloadable products to read/delete an arbitary files.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2019-8092

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can inject arbitrary JavaScript code via email template preview.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2011-1460

    Last Modified: 21 Nov 2024

    WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2019-8090

    Last Modified: 21 Nov 2024

    An arbitrary file deletion vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3. An authenticated users can manipulate the design layout update feature.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2019-6142

    Last Modified: 21 Nov 2024

    It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply the relevant hotfix in order to remediate this issue.

    Published: 5 Nov 2019
    7.8
    High

    CVE-2019-5089

    Last Modified: 21 Nov 2024

    An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a specially crafted JPEG file.

    Published: 5 Nov 2019
    7.8
    High

    CVE-2019-5088

    Last Modified: 21 Nov 2024

    An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially crafted BMP file.

    Published: 5 Nov 2019
    7.2
    High

    CVE-2019-16284

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to execute arbitrary SMM (System Management Mode) code. A list of affected products and versions are available in https://support.hp.com/rs-en/document/c06456250.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19167

    Last Modified: 21 Nov 2024

    CloakCoin through 2.2.2.0 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19166

    Last Modified: 21 Nov 2024

    peercoin through 0.6.4 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19165

    Last Modified: 21 Nov 2024

    neblio through 1.5.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19164

    Last Modified: 21 Nov 2024

    reddcoin through 2.1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19163

    Last Modified: 21 Nov 2024

    stratisX through 2.0.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19162

    Last Modified: 21 Nov 2024

    Divi through 4.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2011-1135

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19161

    Last Modified: 21 Nov 2024

    alqo through 4.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19160

    Last Modified: 21 Nov 2024

    Diamond through 3.0.1.2 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19159

    Last Modified: 21 Nov 2024

    lux through 5.2.2 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19157

    Last Modified: 21 Nov 2024

    Phore through 1.3.3.1 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19156

    Last Modified: 21 Nov 2024

    PIVX through 3.1.03 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2011-1134

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19155

    Last Modified: 21 Nov 2024

    navcoin through 4.3.0 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19154

    Last Modified: 21 Nov 2024

    HTMLCOIN through 2.12 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19153

    Last Modified: 21 Nov 2024

    particl through 0.17 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2018-19152

    Last Modified: 21 Nov 2024

    emercoin through 0.7 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2011-1133

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2019-1982

    Last Modified: 11 Aug 2026

    A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper handling of HTTP requests, including those communicated over a secure HTTPS connection, that contain maliciously crafted headers. An attacker could exploit this vulnerability by sending malicious requests to an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious requests to protected systems, allowing attackers to deliver malicious content that would otherwise be blocked.

    Published: 5 Nov 2019
    5.8
    Medium

    CVE-2019-1981

    Last Modified: 11 Aug 2026

    A vulnerability in the normalization functionality of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to insufficient normalization of a text-based payload. An attacker could exploit this vulnerability by sending traffic that contains specifically obfuscated payloads through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious payloads to protected systems that would otherwise be blocked.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2019-1980

    Last Modified: 11 Aug 2026

    A vulnerability in the protocol detection component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper detection of the initial use of a protocol on a nonstandard port. An attacker could exploit this vulnerability by sending traffic on a nonstandard port for the protocol in use through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious requests to protected systems that would otherwise be blocked. Once the initial protocol flow on the nonstandard port is detected, future flows on the nonstandard port will be successfully detected and handled as configured by the applied policy.

    Published: 5 Nov 2019
    5.8
    Medium

    CVE-2019-1978

    Last Modified: 11 Aug 2026

    A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protections. The vulnerability is due to improper reassembly of traffic streams. An attacker could exploit this vulnerability by sending crafted streams through an affected device. An exploit could allow the attacker to bypass filtering and deliver malicious requests to protected systems that would otherwise be blocked.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2010-3674

    Last Modified: 21 Nov 2024

    TYPO3 before 4.4.1 allows XSS in the frontend search box.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2010-3673

    Last Modified: 21 Nov 2024

    TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-10084

    Last Modified: 21 Nov 2024

    In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms. Session and query IDs are unique and random, but have not been documented or consistently treated as sensitive secrets. Therefore they may be exposed in logs or interfaces. They were also not generated with a cryptographically secure random number generator, so are vulnerable to random number generator attacks that predict future IDs based on past IDs. Impala deployments with Apache Sentry or Apache Ranger authorization enabled may be vulnerable to privilege escalation if an authenticated attacker is able to hijack a session or query from another authenticated user with privileges not assigned to the attacker. Impala deployments with audit logging enabled may be vulnerable to incorrect audit logging as a user could undertake actions that were logged under the name of a different authenticated user. Constructing an attack requires a high degree of technical sophistication and access to the Impala system as an authenticated user.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2019-1877

    Last Modified: 21 Nov 2024

    A vulnerability in the HTTP API of Cisco Enterprise Chat and Email could allow an unauthenticated, remote attacker to download files attached through chat sessions. The vulnerability is due to insufficient authentication mechanisms on the file download function of the API. An attacker could exploit this vulnerability by sending a crafted request to the API. A successful exploit could allow the attacker to download files that other users attach through the chat feature. This vulnerability affects versions prior to 12.0(1)ES1.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2010-3672

    Last Modified: 21 Nov 2024

    TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2005-2354

    Last Modified: 20 Nov 2024

    Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2010-3671

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.

    Published: 5 Nov 2019
    5.5
    Medium

    CVE-2019-1734

    Last Modified: 21 Nov 2024

    A vulnerability in the implementation of a CLI diagnostic command in Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to view sensitive system files that should be restricted. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to incomplete role-based access control (RBAC) verification. An attacker could exploit this vulnerability by authenticating to the device and issuing a specific CLI diagnostic command with crafted user-input parameters. An exploit could allow the attacker to perform an arbitrary read of a file on the device, and the file may contain sensitive information. The attacker needs valid device credentials to exploit this vulnerability.

    Published: 5 Nov 2019
    4.8
    Medium

    CVE-2010-3670

    Last Modified: 21 Nov 2024

    TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.

    Published: 5 Nov 2019
    7.7
    High

    CVE-2019-15966

    Last Modified: 21 Nov 2024

    A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the lack of input validation in the web application. An attacker could exploit this vulnerability by sending a crafted authenticated HTTP request to the device. An exploit could allow the attacker to stop services on an affected device. The device may become inoperable and results in a denial of service (DoS) condition.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-18780

    Last Modified: 21 Nov 2024

    An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.

    Published: 5 Nov 2019
    6.5
    Medium

    CVE-2013-6275

    Last Modified: 21 Nov 2024

    Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-1789

    Last Modified: 21 Nov 2024

    ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scanning PE files. An example is Windows EXE and DLL files that have been packed using Aspack as a result of inadequate bound-checking.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-12625

    Last Modified: 21 Nov 2024

    ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause a denial of service condition by sending crafted messages to an affected system.

    Published: 5 Nov 2019
    —
    Unknown

    CVE-2018-0178

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 5 Nov 2019
    7.8
    High

    CVE-2019-18631

    Last Modified: 21 Nov 2024

    The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows attackers to execute arbitrary code inside the Centrify process via (1) a crafted application that makes a pipe connection to the process and sends malicious serialized data or (2) a crafted Microsoft Management Console snap-in control file.

    Published: 5 Nov 2019
    8.8
    High

    CVE-2019-17062

    Last Modified: 21 Nov 2024

    An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could unintentionally grant unauthorized users access to the admin panel via session fixation.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-17211

    Last Modified: 21 Nov 2024

    An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_packet_data_size_2() is used to calculate the required memory for the CoAP message from the sn_coap_hdr_s data structure. Both returned_byte_count and src_coap_msg_ptr->payload_len are of type uint16_t. When added together, the result returned_byte_count can wrap around the maximum uint16_t value. As a result, insufficient buffer space is allocated for the corresponding CoAP message.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-17212

    Last Modified: 21 Nov 2024

    Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using a while loop. Once an option is parsed in a loop, the current point (*packet_data_pptr) is increased correspondingly. The pointer is restricted by the size of the received buffer, as well as by the 0xFF delimiter byte. Inside each while loop, the check of the value of *packet_data_pptr is not strictly enforced. More specifically, inside a loop, *packet_data_pptr could be increased and then dereferenced without checking. Moreover, there are many other functions in the format of sn_coap_parser_****() that do not check whether the pointer is within the bounds of the allocated buffer. All of these lead to heap-based or stack-based buffer overflows, depending on how the CoAP packet buffer is allocated.

    Published: 5 Nov 2019