CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2019-18705

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18706

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18707

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18708

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18711

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18712

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18713

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18714

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18715

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18716

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18717

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18718

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18721

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2019-18685

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 4 Nov 2019
    7.5
    High

    CVE-2019-17210

    Last Modified: 21 Nov 2024

    A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQTTDeserialize_publish() to get the length and content of the MQTT topic name. In the function readMQTTLenString(), mqttstring->lenstring.len is a part of user input, which can be manipulated. An attacker can simply change it to a larger value to invalidate the if statement so that the statements inside the if statement are skipped, letting the value of mqttstring->lenstring.data default to zero. Later, curn is accessed, which points to mqttstring->lenstring.data. On an Arm Cortex-M chip, the value at address 0x0 is actually the initialization value for the MSP register. It is highly dependent on the actual firmware. Therefore, the behavior of the program is unpredictable from this time on.

    Published: 4 Nov 2019
    7.5
    High

    CVE-2019-18178

    Last Modified: 21 Nov 2024

    Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), but it is reused to flush modified file content from the cache to disk by the function FF_FlushCache().

    Published: 4 Nov 2019
    9.8
    Critical

    CVE-2019-18663

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 4 Nov 2019
    6.5
    Medium

    CVE-2019-13497

    Last Modified: 21 Nov 2024

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.

    Published: 4 Nov 2019
    8.1
    High

    CVE-2019-13496

    Last Modified: 21 Nov 2024

    One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the One Identity Defender product, and replacing a failed SAML response with a successful SAML response.

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-2257

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness

    Published: 4 Nov 2019
    5.3
    Medium

    CVE-2013-2258

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 has Nickname User Impersonation

    Published: 4 Nov 2019
    9.8
    Critical

    CVE-2013-2259

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-4105

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure

    Published: 4 Nov 2019
    9.8
    Critical

    CVE-2013-2260

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness

    Published: 4 Nov 2019
    7
    High

    CVE-2019-18684

    Last Modified: 21 Nov 2024

    Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo process. This occurs because of a race condition between determining a uid, and the setresuid and openat system calls. The attacker can write "ALL ALL=(ALL) NOPASSWD:ALL" to /proc/#####/fd/3 at a time when Sudo is prompting for a password. NOTE: This has been disputed due to the way Linux /proc works. It has been argued that writing to /proc/#####/fd/3 would only be viable if you had permission to write to /etc/sudoers. Even with write permission to /proc/#####/fd/3, it would not help you write to /etc/sudoers

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-2262

    Last Modified: 21 Nov 2024

    Cryptocat strophe.js before 2.0.22 has information disclosure

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-2261

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-4104

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-4100

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 has Remote Denial of Service via username

    Published: 4 Nov 2019
    —
    Unknown

    CVE-2017-3989

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 4 Nov 2019
    5.3
    Medium

    CVE-2013-4101

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness

    Published: 4 Nov 2019
    9.1
    Critical

    CVE-2013-4102

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness

    Published: 4 Nov 2019
    8.8
    High

    CVE-2018-19031

    Last Modified: 21 Nov 2024

    A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.

    Published: 4 Nov 2019
    9.8
    Critical

    CVE-2013-4103

    Last Modified: 21 Nov 2024

    Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

    Published: 4 Nov 2019
    7.5
    High

    CVE-2019-0350

    Last Modified: 21 Nov 2024

    SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which crashes the indexserver of an SAP HANA instance, leading to Denial of Service

    Published: 4 Nov 2019
    7.5
    High

    CVE-2013-4412

    Last Modified: 21 Nov 2024

    slim has NULL pointer dereference when using crypt() method from glibc 2.17

    Published: 4 Nov 2019
    6.5
    Medium

    CVE-2019-14824

    Last Modified: 13 Feb 2025

    A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

    Published: 4 Nov 2019
    8.1
    High

    CVE-2019-20920

    Last Modified: 21 Nov 2024

    Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).

    Published: 4 Nov 2019
    7
    High

    CVE-2019-18683

    Last Modified: 21 Nov 2024

    An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this driver (part of the V4L2 subsystem). These issues are caused by wrong mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(), sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these race conditions leads to a use-after-free.

    Published: 4 Nov 2019
    6.3
    Medium

    CVE-2019-19529

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c driver, aka CID-4d6636498c41.

    Published: 4 Nov 2019
    2.4
    Low

    CVE-2019-19534

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.3.11, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c driver, aka CID-f7a1337f0d29.

    Published: 4 Nov 2019
    7.5
    High

    CVE-2019-20922

    Last Modified: 21 Nov 2024

    Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

    Published: 4 Nov 2019
    6.1
    Medium

    CVE-2019-18860

    Last Modified: 5 Nov 2025

    Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

    Published: 3 Nov 2019
    8.8
    High

    CVE-2019-3864

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in all quay-2 versions before quay-3.0.0, in the Quay web GUI where POST requests include a specific parameter which is used as a CSRF token. The token is not refreshed for every request or when a user logged out and in again. An attacker could use a leaked token to gain access to the system using the user's account.

    Published: 3 Nov 2019
    5.5
    Medium

    CVE-2019-19479

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.

    Published: 3 Nov 2019
    6.1
    Medium

    CVE-2019-3865

    Last Modified: 21 Nov 2024

    A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.

    Published: 3 Nov 2019
    4.6
    Medium

    CVE-2019-14360

    Last Modified: 4 Jun 2026

    On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data.

    Published: 2 Nov 2019
    4.6
    Medium

    CVE-2019-14358

    Last Modified: 21 Nov 2024

    On Archos Safe-T devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data.

    Published: 2 Nov 2019
    4.6
    Medium

    CVE-2019-18673

    Last Modified: 21 Nov 2024

    On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. Note: BIP39 secrets are not displayed by default on this device. The side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data.

    Published: 2 Nov 2019
    6.5
    Medium

    CVE-2019-18668

    Last Modified: 21 Nov 2024

    An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an attacker provides a currency that does not exist and is worth less than this default, the attacker can eventually purchase an item for a significantly cheaper price.

    Published: 2 Nov 2019