CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-17598

    Last Modified: 21 Nov 2024

    An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2013-6365

    Last Modified: 21 Nov 2024

    Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

    Published: 5 Nov 2019
    8.8
    High

    CVE-2013-6364

    Last Modified: 21 Nov 2024

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-17221

    Last Modified: 21 Nov 2024

    PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of the webpage module, which loads a specified URL and calls a given callback. An attacker can supply a specially crafted HTML file, as user input, that allows reading arbitrary files on the filesystem. For example, if page.render() is the function callback, this generates a PDF or an image of the targeted file. NOTE: this product is no longer developed.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2013-4110

    Last Modified: 21 Nov 2024

    Cryptocat has an Unspecified Chat Participant User List Disclosure

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2013-4107

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting

    Published: 5 Nov 2019
    7.4
    High

    CVE-2019-3685

    Last Modified: 21 Nov 2024

    Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client binary

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-18676

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach the proxy port can trivially perform the attack via a crafted URI scheme.

    Published: 5 Nov 2019
    5.3
    Medium

    CVE-2019-18678

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

    Published: 5 Nov 2019
    9.1
    Critical

    CVE-2019-12523

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.

    Published: 5 Nov 2019
    5.5
    Medium

    CVE-2020-10769

    Last Modified: 21 Nov 2024

    A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment boundary guidelines, it causes a buffer over-read threat, leading to a system crash. This flaw allows a local attacker with user privileges to cause a denial of service.

    Published: 5 Nov 2019
    9.8
    Critical

    CVE-2019-12526

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.

    Published: 5 Nov 2019
    6.1
    Medium

    CVE-2019-18677

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

    Published: 5 Nov 2019
    7.5
    High

    CVE-2019-18679

    Last Modified: 21 Nov 2024

    An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

    Published: 5 Nov 2019
    5.4
    Medium

    CVE-2010-3669

    Last Modified: 21 Nov 2024

    TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.

    Published: 4 Nov 2019
    7.5
    High

    CVE-2010-3668

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.

    Published: 4 Nov 2019
    5.3
    Medium

    CVE-2010-3667

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.

    Published: 4 Nov 2019
    5.3
    Medium

    CVE-2010-3666

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.

    Published: 4 Nov 2019
    5.4
    Medium

    CVE-2010-3665

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.

    Published: 4 Nov 2019
    6.5
    Medium

    CVE-2010-3664

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.

    Published: 4 Nov 2019
    8.8
    High

    CVE-2010-3663

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute arbitrary code on the backend.

    Published: 4 Nov 2019
    8.8
    High

    CVE-2010-3662

    Last Modified: 21 Nov 2024

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.

    Published: 4 Nov 2019
    9.8
    Critical

    CVE-2013-4409

    Last Modified: 21 Nov 2024

    An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

    Published: 4 Nov 2019
    9.8
    Critical

    CVE-2015-8980

    Last Modified: 21 Nov 2024

    The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18760

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18761

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18762

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18763

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18764

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18765

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18766

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18767

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18768

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18769

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18770

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18771

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18772

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18773

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18774

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18738

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18722

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18723

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18724

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18725

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18726

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18727

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18728

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18729

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18730

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18731

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019