CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-6851

    Last Modified: 21 Nov 2024

    A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information from the controller when using TFTP protocol.

    Published: 29 Oct 2019
    7.5
    High

    CVE-2019-6850

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when reading specific registers with the REST API of the controller/communication module.

    Published: 29 Oct 2019
    7.5
    High

    CVE-2019-6849

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, which could cause the disclosure of sensitive information when using specific Modbus services provided by the REST API of the controller/communication module.

    Published: 29 Oct 2019
    8.6
    High

    CVE-2019-6848

    Last Modified: 21 Nov 2024

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M580 communication module (BMENOC0311, BMENOC0321) (see notification for version info), which could cause a Denial of Service attack on the PLC when sending specific data on the REST API of the controller/communication module.

    Published: 29 Oct 2019
    4.9
    Medium

    CVE-2019-6847

    Last Modified: 21 Nov 2024

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the FTP service when upgrading the firmware with a version incompatible with the application in the controller using FTP protocol.

    Published: 29 Oct 2019
    6.5
    Medium

    CVE-2019-6846

    Last Modified: 21 Nov 2024

    A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause information disclosure when using the FTP protocol.

    Published: 29 Oct 2019
    7.5
    High

    CVE-2019-6845

    Last Modified: 21 Nov 2024

    A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon Premium , Modicon Quantum (all firmware versions), which could cause the disclosure of information when transferring applications to the controller using Modbus TCP protocol.

    Published: 29 Oct 2019
    4.9
    Medium

    CVE-2019-6844

    Last Modified: 21 Nov 2024

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service atack on the PLC when upgrading the controller with a firmware package containing an invalid web server image using FTP protocol.

    Published: 29 Oct 2019
    4.9
    Medium

    CVE-2019-6843

    Last Modified: 21 Nov 2024

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the controller with an empty firmware package using FTP protocol.

    Published: 29 Oct 2019
    4.9
    Medium

    CVE-2019-6842

    Last Modified: 21 Nov 2024

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with a missing web server image inside the package using FTP protocol.

    Published: 29 Oct 2019
    4.9
    Medium

    CVE-2019-6841

    Last Modified: 21 Nov 2024

    A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior to V3.10), Modicon M340 (all firmware versions), and Modicon BMxCRA and 140CRA modules (all firmware versions), which could cause a Denial of Service attack on the PLC when upgrading the firmware with no firmware image inside the package using FTP protocol.

    Published: 29 Oct 2019
    7.5
    High

    CVE-2019-18602

    Last Modified: 21 Nov 2024

    OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.

    Published: 29 Oct 2019
    5.9
    Medium

    CVE-2019-18603

    Last Modified: 21 Nov 2024

    OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.

    Published: 29 Oct 2019
    7.5
    High

    CVE-2019-18601

    Last Modified: 21 Nov 2024

    OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler.

    Published: 29 Oct 2019
    7.5
    High

    CVE-2012-0046

    Last Modified: 21 Nov 2024

    mediawiki allows deleted text to be exposed

    Published: 29 Oct 2019
    7.5
    High

    CVE-2011-4931

    Last Modified: 21 Nov 2024

    gpw generates shorter passwords than required

    Published: 29 Oct 2019
    9.8
    Critical

    CVE-2012-1187

    Last Modified: 21 Nov 2024

    Bitlbee does not drop extra group privileges correctly in unix.c

    Published: 29 Oct 2019
    7.5
    High

    CVE-2009-3723

    Last Modified: 21 Nov 2024

    asterisk allows calls on prohibited networks

    Published: 29 Oct 2019
    9.8
    Critical

    CVE-2010-3375

    Last Modified: 21 Nov 2024

    qtparted has insecure library loading which may allow arbitrary code execution

    Published: 29 Oct 2019
    5.5
    Medium

    CVE-2010-3373

    Last Modified: 21 Nov 2024

    paxtest handles temporary files insecurely

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-8720

    Last Modified: 18 Nov 2025

    A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-13720

    Last Modified: 24 Oct 2025

    Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Oct 2019
    6.5
    Medium

    CVE-2019-10218

    Last Modified: 21 Nov 2024

    A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current working directory using the privileges of the client user.

    Published: 29 Oct 2019
    5.4
    Medium

    CVE-2019-14833

    Last Modified: 21 Nov 2024

    A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it vulnerable to dictionary attacks.

    Published: 29 Oct 2019
    6.1
    Medium

    CVE-2019-8719

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 29 Oct 2019
    6.5
    Medium

    CVE-2019-18853

    Last Modified: 21 Nov 2024

    ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly restricted in coders/svg.c, related to SVG and libxml2.

    Published: 29 Oct 2019
    4.9
    Medium

    CVE-2019-14847

    Last Modified: 21 Nov 2024

    A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.

    Published: 29 Oct 2019
    6.5
    Medium

    CVE-2019-14860

    Last Modified: 21 Nov 2024

    It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-8707

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-8726

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 29 Oct 2019
    5.3
    Medium

    CVE-2019-8768

    Last Modified: 21 Nov 2024

    "Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Catalina 10.15. A user may be unable to delete browsing history items.

    Published: 29 Oct 2019
    6.1
    Medium

    CVE-2019-8771

    Last Modified: 21 Nov 2024

    This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 13.0.1, iOS 13. Maliciously crafted web content may violate iframe sandboxing policy.

    Published: 29 Oct 2019
    9.8
    Critical

    CVE-2019-18604

    Last Modified: 21 Nov 2024

    In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.

    Published: 29 Oct 2019
    6.1
    Medium

    CVE-2019-8625

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 29 Oct 2019
    6.1
    Medium

    CVE-2019-8674

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-8733

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-8735

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 29 Oct 2019
    8.8
    High

    CVE-2019-8763

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.1 and iPadOS 13.1, tvOS 13, Safari 13.0.1, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 29 Oct 2019
    4.3
    Medium

    CVE-2019-8769

    Last Modified: 21 Nov 2024

    An issue existed in the drawing of web page elements. The issue was addressed with improved logic. This issue is fixed in iOS 13.1 and iPadOS 13.1, macOS Catalina 10.15. Visiting a maliciously crafted website may reveal browsing history.

    Published: 29 Oct 2019
    5.3
    Medium

    CVE-2019-4600

    Last Modified: 21 Nov 2024

    IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially crafted HTTP request. IBM X-Force ID: 167883.

    Published: 28 Oct 2019
    8.8
    High

    CVE-2019-4546

    Last Modified: 21 Nov 2024

    After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges that they are not normally allowed to access. IBM X-Force ID: 165948.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-4339

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 161418.

    Published: 28 Oct 2019
    4.3
    Medium

    CVE-2019-4330

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.

    Published: 28 Oct 2019
    4.3
    Medium

    CVE-2019-4329

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 161209.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-4314

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force ID: 1610141.

    Published: 28 Oct 2019
    5.3
    Medium

    CVE-2019-4311

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 161037.

    Published: 28 Oct 2019
    5.5
    Medium

    CVE-2019-4309

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to obtain highly sensitive information. IBM X-Force ID: 161035.

    Published: 28 Oct 2019
    5.5
    Medium

    CVE-2019-4307

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 160987.

    Published: 28 Oct 2019
    6.5
    Medium

    CVE-2019-4306

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence (SonarG) 4.0 specifies permissions for a security-critical resource which could lead to the exposure of sensitive information or the modification of that resource by unintended parties. IBM X-Force ID: 160986.

    Published: 28 Oct 2019
    4.3
    Medium

    CVE-2019-5533

    Last Modified: 21 Nov 2024

    In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone numbers and e-mail address if present but no other personal data. VMware has evaluated the severity of this issue to be in the moderate severity range with a maximum CVSSv3 base score of 4.3.

    Published: 28 Oct 2019