CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-1750

    Last Modified: 21 Nov 2024

    A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods in the OpenShift cluster. This was fixed in openshift/machine-config-operator 4.4.3, openshift/machine-config-operator 4.3.25, openshift/machine-config-operator 4.2.36.

    Published: 28 Oct 2019
    7.5
    High

    CVE-2019-18813

    Last Modified: 21 Nov 2024

    A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8.

    Published: 27 Oct 2019
    6.1
    Medium

    CVE-2019-18221

    Last Modified: 21 Nov 2024

    CoreHR Core Portal before 27.0.7 allows stored XSS.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2017-14742

    Last Modified: 21 Nov 2024

    Buffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.

    Published: 25 Oct 2019
    4.3
    Medium

    CVE-2019-17138

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion from JPEG to EPS. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8809.

    Published: 25 Oct 2019
    4.3
    Medium

    CVE-2019-17143

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWG files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-9273.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-17139

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of Javascript in the HTML2PDF plugin. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8692.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-17141

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-17142

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Keystroke action of a listbox field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9081.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-17140

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the OnFocus event. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9091.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-17144

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of DWG files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9274.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-17145

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of DXF files to PDF. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9276.

    Published: 25 Oct 2019
    7.5
    High

    CVE-2019-5508

    Last Modified: 21 Nov 2024

    Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS).

    Published: 25 Oct 2019
    5.3
    Medium

    CVE-2019-13525

    Last Modified: 21 Nov 2024

    In IP-AK2 Access Control Panel Version 1.04.07 and prior, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data, which can be accessed without authentication over the network.

    Published: 25 Oct 2019
    6.8
    Medium

    CVE-2019-13546

    Last Modified: 21 Nov 2024

    In IntelliSpace Perinatal, Versions K and prior, a vulnerability within the IntelliSpace Perinatal application environment could enable an unauthorized attacker with physical access to a locked application screen, or an authorized remote desktop session host application user to break-out from the containment of the application and access unauthorized resources from the Windows operating system as the limited-access Windows user. Due to potential Windows vulnerabilities, it may be possible for additional attack methods to be used to escalate privileges on the operating system.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-13553

    Last Modified: 21 Nov 2024

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the affected systems, namely turning the cooling unit on and off and setting the temperature set point.

    Published: 25 Oct 2019
    7.5
    High

    CVE-2019-13549

    Last Modified: 21 Nov 2024

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5119

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exist in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configurations, access the underlying operating system.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5120

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configurations, access the underlying operating system.

    Published: 25 Oct 2019
    9.9
    Critical

    CVE-2019-5114

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and,in certain configuration, access the underlying operating system.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5123

    Last Modified: 21 Nov 2024

    Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5122

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5121

    Last Modified: 21 Nov 2024

    SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter uuid in /objects/pluginSwitch.json.php

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5117

    Last Modified: 21 Nov 2024

    Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configuration, access the underlying operating system.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2019-5116

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a SQL injection. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configuration, access the underlying operating system.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-5129

    Last Modified: 21 Nov 2024

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getSpiritsFromVideo.php is vulnerable to a command injection attack.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-5128

    Last Modified: 21 Nov 2024

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-5127

    Last Modified: 21 Nov 2024

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImage.php is vulnerable to a command injection attack.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-16265

    Last Modified: 21 Nov 2024

    CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.

    Published: 25 Oct 2019
    5.4
    Medium

    CVE-2019-4461

    Last Modified: 21 Nov 2024

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.

    Published: 25 Oct 2019
    4.3
    Medium

    CVE-2019-4400

    Last Modified: 21 Nov 2024

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162261.

    Published: 25 Oct 2019
    7.5
    High

    CVE-2019-4399

    Last Modified: 21 Nov 2024

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 162260.

    Published: 25 Oct 2019
    5.4
    Medium

    CVE-2019-4396

    Last Modified: 21 Nov 2024

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 162236.

    Published: 25 Oct 2019
    3.3
    Low

    CVE-2019-4395

    Last Modified: 21 Nov 2024

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 could allow a local user to obtain sensitive information from temporary script files. IBM X-Force ID: 162333.

    Published: 25 Oct 2019
    2.3
    Low

    CVE-2019-4394

    Last Modified: 21 Nov 2024

    IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-Force ID: 162232.

    Published: 25 Oct 2019
    7.5
    High

    CVE-2019-4036

    Last Modified: 13 Feb 2025

    IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse proxy component. IBM X-Force ID: 156159.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-14451

    Last Modified: 21 Nov 2024

    RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined with CVE-2019-14450, an attacker can upload an "external command" configuration as a printer configuration, and achieve remote code execution. After exploitation, loading of the external command configuration is dependent on a system reboot or service restart.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2013-4658

    Last Modified: 21 Nov 2024

    Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2013-4848

    Last Modified: 21 Nov 2024

    TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.

    Published: 25 Oct 2019
    8.8
    High

    CVE-2013-4855

    Last Modified: 21 Nov 2024

    D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.

    Published: 25 Oct 2019
    6.5
    Medium

    CVE-2013-4856

    Last Modified: 21 Nov 2024

    D-Link DIR-865L has Information Disclosure.

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2013-4857

    Last Modified: 21 Nov 2024

    D-Link DIR-865L has PHP File Inclusion in the router xml file.

    Published: 25 Oct 2019
    —
    Unknown

    CVE-2017-9688

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Oct 2019
    —
    Unknown

    CVE-2017-15840

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Oct 2019
    —
    Unknown

    CVE-2017-15839

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Oct 2019
    6.5
    Medium

    CVE-2019-8234

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a cross-site request forgery vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 25 Oct 2019
    —
    Unknown

    CVE-2017-15838

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Oct 2019
    —
    Unknown

    CVE-2017-15816

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Oct 2019
    —
    Unknown

    CVE-2017-11008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Oct 2019
    9.8
    Critical

    CVE-2019-8088

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 25 Oct 2019