CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-16973

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2019-16972

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2019-16971

    Last Modified: 21 Nov 2024

    In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2015-9501

    Last Modified: 21 Nov 2024

    The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2015-9500

    Last Modified: 21 Nov 2024

    The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2019-8089

    Last Modified: 21 Nov 2024

    Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 22 Oct 2019
    9.8
    Critical

    CVE-2015-9499

    Last Modified: 21 Nov 2024

    The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2015-9498

    Last Modified: 21 Nov 2024

    The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2015-9497

    Last Modified: 21 Nov 2024

    The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2015-9496

    Last Modified: 21 Nov 2024

    The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2015-9495

    Last Modified: 21 Nov 2024

    The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2015-9494

    Last Modified: 21 Nov 2024

    The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2015-9493

    Last Modified: 21 Nov 2024

    The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.

    Published: 22 Oct 2019
    2.4
    Low

    CVE-2017-8087

    Last Modified: 21 Nov 2024

    Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate attackers to view slices of previously transmitted packets or portions of memory via via unspecified vectors.

    Published: 22 Oct 2019
    9.8
    Critical

    CVE-2019-12147

    Last Modified: 21 Nov 2024

    The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that user to login to the system (either via the web interface or via SSH) to achieve complete compromise of the device. This affects /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt.

    Published: 22 Oct 2019
    7.5
    High

    CVE-2019-10079

    Last Modified: 21 Nov 2024

    Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't limit the number of setting frames sent from the client using the HTTP/2 protocol. Users should upgrade to Apache Traffic Server 7.1.7, 8.0.4, or later versions.

    Published: 22 Oct 2019
    9.8
    Critical

    CVE-2019-12148

    Last Modified: 21 Nov 2024

    The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login into the device's admin web portal without providing any credentials. This affects /var/webconfig/gui/Webconfig.inc.php.

    Published: 22 Oct 2019
    7.5
    High

    CVE-2019-12290

    Last Modified: 21 Nov 2024

    GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.

    Published: 22 Oct 2019
    6.5
    Medium

    CVE-2019-12967

    Last Modified: 21 Nov 2024

    Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.

    Published: 22 Oct 2019
    5.9
    Medium

    CVE-2019-11674

    Last Modified: 21 Nov 2024

    Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.

    Published: 22 Oct 2019
    5.4
    Medium

    CVE-2019-17189

    Last Modified: 21 Nov 2024

    totemodata 3.0.0_b936 has XSS via a folder name.

    Published: 22 Oct 2019
    7.8
    High

    CVE-2019-4523

    Last Modified: 21 Nov 2024

    IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481.

    Published: 22 Oct 2019
    7.8
    High

    CVE-2019-17424

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows remote attackers (serving firewall configuration files) to achieve Remote Code Execution or Denial Of Service via a crafted file.

    Published: 22 Oct 2019
    6.5
    Medium

    CVE-2019-14864

    Last Modified: 21 Nov 2024

    Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-11759

    Last Modified: 21 Nov 2024

    An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    5.4
    Medium

    CVE-2019-11761

    Last Modified: 21 Nov 2024

    By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13705

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.

    Published: 22 Oct 2019
    5.3
    Medium

    CVE-2019-13711

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13715

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13717

    Last Modified: 21 Nov 2024

    Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.

    Published: 22 Oct 2019
    5.3
    Medium

    CVE-2019-18282

    Last Modified: 21 Nov 2024

    The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashrnd value as a secret, and because jhash (instead of siphash) is used. The hashrnd value remains the same starting from boot time, and can be inferred by an attacker. This affects net/core/flow_dissector.c and related code.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-11757

    Last Modified: 21 Nov 2024

    When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-11758

    Last Modified: 21 Nov 2024

    Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-11760

    Last Modified: 21 Nov 2024

    A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2019-11762

    Last Modified: 21 Nov 2024

    If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2019-11763

    Last Modified: 21 Nov 2024

    Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-11764

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-13699

    Last Modified: 21 Nov 2024

    Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13701

    Last Modified: 21 Nov 2024

    Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13703

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 22 Oct 2019
    7.8
    High

    CVE-2019-13706

    Last Modified: 21 Nov 2024

    Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 22 Oct 2019
    5.5
    Medium

    CVE-2019-13707

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13708

    Last Modified: 21 Nov 2024

    Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 22 Oct 2019
    6.5
    Medium

    CVE-2019-13709

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13710

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page.

    Published: 22 Oct 2019
    6.1
    Medium

    CVE-2019-13714

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13718

    Last Modified: 21 Nov 2024

    Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 22 Oct 2019
    4.3
    Medium

    CVE-2019-13719

    Last Modified: 21 Nov 2024

    Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page.

    Published: 22 Oct 2019
    8.8
    High

    CVE-2019-13700

    Last Modified: 21 Nov 2024

    Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 22 Oct 2019
    7.8
    High

    CVE-2019-13702

    Last Modified: 21 Nov 2024

    Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.

    Published: 22 Oct 2019