CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2018-4031

    Last Modified: 21 Nov 2024

    An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua statement without prior sanitization, which results in arbitrary Lua script execution in the kernel. An attacker could send an HTTP request to exploit this vulnerability.

    Published: 31 Oct 2019
    7.1
    High

    CVE-2018-4064

    Last Modified: 21 Nov 2024

    An exploitable unverified password change vulnerability exists in the ACEManager upload.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can cause a unverified device configuration change, resulting in an unverified change of the user password on the device. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 31 Oct 2019
    5.9
    Medium

    CVE-2019-5023

    Last Modified: 21 Nov 2024

    An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linux-4.9.8-test1 to 4.9.24-test7, grsecurity official from version grsecurity-3.1-4.9.8-201702060653 to grsecurity-3.1-4.9.24-201704252333, grsecurity unofficial from version v4.9.25-unofficialgrsec to v4.9.74-unofficialgrsec. PaX adds a temp buffer to the read_kmem function, which is never freed when an invalid address is supplied. This results in a memory leakage that can lead to a crash of the system. An attacker needs to induce a read to /dev/kmem using an invalid address to exploit this vulnerability.

    Published: 31 Oct 2019
    8.8
    High

    CVE-2019-5030

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro MR1 (7,0,2019,0220). While parsing a document text info container, the TxMasterStyleAtom::parse function is incorrectly checking the bounds corresponding to the number of style levels, causing a vtable pointer to be overwritten, which leads to code execution.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2019-5043

    Last Modified: 21 Nov 2024

    An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A set of TCP connections can cause unrestricted resource allocation, resulting in a denial of service. An attacker can connect multiple times to trigger this vulnerability.

    Published: 31 Oct 2019
    8.8
    High

    CVE-2013-2024

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.

    Published: 31 Oct 2019
    10
    Critical

    CVE-2019-5049

    Last Modified: 21 Nov 2024

    An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002. A specially crafted pixel shader can cause an out-of-bounds memory write. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.

    Published: 31 Oct 2019
    4.3
    Medium

    CVE-2019-5095

    Last Modified: 21 Nov 2024

    An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticated users can obtain the summary for issues they do not have permission to view via the Tempo plugin.

    Published: 31 Oct 2019
    7.3
    High

    CVE-2013-2012

    Last Modified: 21 Nov 2024

    autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.

    Published: 31 Oct 2019
    10
    Critical

    CVE-2019-5151

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 31 Oct 2019
    6.1
    Medium

    CVE-2013-1951

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.

    Published: 31 Oct 2019
    8.9
    High

    CVE-2019-5150

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 31 Oct 2019
    7.2
    High

    CVE-2019-15710

    Last Modified: 21 Nov 2024

    An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.

    Published: 31 Oct 2019
    7.2
    High

    CVE-2019-18396

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.

    Published: 31 Oct 2019
    5.4
    Medium

    CVE-2013-1934

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value.

    Published: 31 Oct 2019
    5.4
    Medium

    CVE-2013-1932

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via a project name.

    Published: 31 Oct 2019
    6.1
    Medium

    CVE-2013-1931

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.

    Published: 31 Oct 2019
    4.3
    Medium

    CVE-2013-1930

    Last Modified: 21 Nov 2024

    MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18657

    Last Modified: 25 Jun 2025

    ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-14356

    Last Modified: 21 Nov 2024

    On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. NOTE: At Coinkite, we’ve already mitigated it, even though we feel strongly that it is not a legitimate issue. In our opinion, it is both unproven (might not even work) and also completely impractical—even if it could be made to work perfectly

    Published: 31 Oct 2019
    6.1
    Medium

    CVE-2019-18656

    Last Modified: 21 Nov 2024

    Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-18464

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3), multiple SQL Injection vulnerabilities have been found in the REST API that could allow an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database or may be able to alter the database.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-18465

    Last Modified: 21 Nov 2024

    In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the MySQL database is being used.

    Published: 31 Oct 2019
    4.3
    Medium

    CVE-2019-16251

    Last Modified: 21 Nov 2024

    plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

    Published: 31 Oct 2019
    7.8
    High

    CVE-2019-12612

    Last Modified: 21 Nov 2024

    An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitrary code to the BOX appliance via the web API. In order to exploit this vulnerability, an attacker needs presence in Bitdefender BOX setup network and Bitdefender BOX be in setup mode.

    Published: 31 Oct 2019
    9.1
    Critical

    CVE-2009-5042

    Last Modified: 21 Nov 2024

    python-docutils allows insecure usage of temporary files

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2009-5041

    Last Modified: 21 Nov 2024

    overkill has buffer overflow via long player names that can corrupt data on the server machine

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2009-5043

    Last Modified: 21 Nov 2024

    burn allows file names to escape via mishandled quotation marks

    Published: 31 Oct 2019
    8
    High

    CVE-2019-3421

    Last Modified: 21 Nov 2024

    The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection vulnerability. Unauthorized users can exploit this vulnerability to control the user terminal system.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18369

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

    Published: 31 Oct 2019
    7.3
    High

    CVE-2019-18368

    Last Modified: 21 Nov 2024

    In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.

    Published: 31 Oct 2019
    6.5
    Medium

    CVE-2010-2490

    Last Modified: 21 Nov 2024

    Mumble: murmur-server has DoS due to malformed client query

    Published: 31 Oct 2019
    5.7
    Medium

    CVE-2019-3419

    Last Modified: 21 Nov 2024

    A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker could exploit this vulnerability to build a link to the device and send specific packets to cause a denial of service.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18367

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18366

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.

    Published: 31 Oct 2019
    4.3
    Medium

    CVE-2019-18365

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-18364

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2018-21030

    Last Modified: 21 Nov 2024

    Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18363

    Last Modified: 21 Nov 2024

    In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration under some circumstances.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18362

    Last Modified: 21 Nov 2024

    JetBrains MPS before 2019.2.2 exposed listening ports to the network.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18361

    Last Modified: 21 Nov 2024

    JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code execution.

    Published: 31 Oct 2019
    5.3
    Medium

    CVE-2019-18360

    Last Modified: 21 Nov 2024

    In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.

    Published: 31 Oct 2019
    6.1
    Medium

    CVE-2019-17551

    Last Modified: 21 Nov 2024

    In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a malicious payload to /WFS/agreementView.faces allowing a stored XSS via the mainForm:loanNotesnotes:0:rich_text_editor_note_text parameter in the Notes section. Although versions 6.31.8.3 and 6.31.8.5 are confirmed to be affected, all versions with the vulnerable WYSIWYG editor in the Notes section are likely affected.

    Published: 31 Oct 2019
    6.5
    Medium

    CVE-2019-18420

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling for a bad format character was done using BUG(), which crashes Xen. One path, via the VCPUOP_initialise hypercall, has a bad format character. The BUG() can be hit if VCPUOP_initialise executes for a sufficiently long period of time for a continuation to be created. Malicious guests may cause a hypervisor crash, resulting in a Denial of Service (DoS). Xen versions 4.6 and newer are vulnerable. Xen versions 4.5 and earlier are not vulnerable. Only x86 PV guests can exploit the vulnerability. HVM and PVH guests, and guests on ARM systems, cannot exploit the vulnerability.

    Published: 31 Oct 2019
    7.5
    High

    CVE-2019-18421

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for PV guests, Xen exposes the actual hardware pagetables to the guest. In order to prevent the guest from modifying these page tables directly, Xen keeps track of how pages are used using a type system; pages must be "promoted" before being used as a pagetable, and "demoted" before being used for any other type. Xen also allows for "recursive" promotions: i.e., an operating system promoting a page to an L4 pagetable may end up causing pages to be promoted to L3s, which may in turn cause pages to be promoted to L2s, and so on. These operations may take an arbitrarily large amount of time, and so must be re-startable. Unfortunately, making recursive pagetable promotion and demotion operations restartable is incredibly complicated, and the code contains several races which, if triggered, can cause Xen to drop or retain extra type counts, potentially allowing guests to get write access to in-use pagetables. A malicious PV guest administrator may be able to escalate their privilege to that of the host. All x86 systems with untrusted PV guests are vulnerable. HVM and PVH guests cannot exercise this vulnerability.

    Published: 31 Oct 2019
    6.8
    Medium

    CVE-2019-18424

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to program the device to DMA to an arbitrary address. The IOMMU is used to protect the host from malicious DMA by making sure that the device addresses can only target memory assigned to the guest. However, when the guest domain is torn down, or the device is deassigned, the device is assigned back to dom0, thus allowing any in-flight DMA to potentially target critical host data. An untrusted domain with access to a physical device can DMA into host memory, leading to privilege escalation. Only systems where guests are given direct access to physical devices capable of DMA (PCI pass-through) are vulnerable. Systems which do not use PCI pass-through are not vulnerable.

    Published: 31 Oct 2019
    8.8
    High

    CVE-2019-18423

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() and p2m_get_entry() to sanity check guest physical frame. The rest of the code in the two functions will assume that there is a valid root table and check that with BUG_ON(). The function p2m_get_root_pointer() will ignore the unused top bits of a guest physical frame. This means that the function p2m_set_entry() will alias the frame. However, p2m->max_mapped_gfn will be updated using the original frame. It would be possible to set p2m->max_mapped_gfn high enough to cover a frame that would lead p2m_get_root_pointer() to return NULL in p2m_get_entry() and p2m_resolve_translation_fault(). Additionally, the sanity check on p2m->max_mapped_gfn is off-by-one allowing "highest mapped + 1" to be considered valid. However, p2m_get_root_pointer() will return NULL. The problem could be triggered with a specially crafted hypercall XENMEM_add_to_physmap{, _batch} followed by an access to an address (via hypercall or direct access) that passes the sanity check but cause p2m_get_root_pointer() to return NULL. A malicious guest administrator may cause a hypervisor crash, resulting in a Denial of Service (DoS). Xen version 4.8 and newer are vulnerable. Only Arm systems are vulnerable. x86 systems are not affected.

    Published: 31 Oct 2019
    8.8
    High

    CVE-2019-18422

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an exception occurs on an ARM system which is handled without changing processor level, some interrupts are unconditionally enabled during exception entry. So exceptions which occur when interrupts are masked will effectively unmask the interrupts. A malicious guest might contrive to arrange for critical Xen code to run with interrupts erroneously enabled. This could lead to data corruption, denial of service, or possibly even privilege escalation. However a precise attack technique has not been identified.

    Published: 31 Oct 2019
    9.8
    Critical

    CVE-2019-18425

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table accesses are performed by the emulating code. Such accesses should respect the guest specified limits, unless otherwise guaranteed to fail in such a case. Without this, emulation of 32-bit guest user mode calls through call gates would allow guest user mode to install and then use descriptors of their choice, as long as the guest kernel did not itself install an LDT. (Most OSes don't install any LDT by default). 32-bit PV guest user mode can elevate its privileges to that of the guest kernel. Xen versions from at least 3.2 onwards are affected. Only 32-bit PV guest user mode can leverage this vulnerability. HVM, PVH, as well as 64-bit PV guests cannot leverage this vulnerability. Arm systems are unaffected.

    Published: 31 Oct 2019
    5.9
    Medium

    CVE-2019-18644

    Last Modified: 21 Nov 2024

    The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic link attacks allow privileged files to be deleted.

    Published: 30 Oct 2019