CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-2110

    Last Modified: 21 Nov 2024

    In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-69703445

    Published: 11 Oct 2019
    8.8
    High

    CVE-2019-2186

    Last Modified: 21 Nov 2024

    In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-136175447

    Published: 11 Oct 2019
    8.8
    High

    CVE-2019-2185

    Last Modified: 21 Nov 2024

    In VlcDequantH263IntraBlock_SH of vlc_dequant.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-136173699

    Published: 11 Oct 2019
    8.8
    High

    CVE-2019-2184

    Last Modified: 21 Nov 2024

    In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-134578122

    Published: 11 Oct 2019
    7.8
    High

    CVE-2019-2173

    Last Modified: 21 Nov 2024

    In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-123013720

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9492

    Last Modified: 21 Nov 2024

    The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9491

    Last Modified: 21 Nov 2024

    The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9490

    Last Modified: 21 Nov 2024

    The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9489

    Last Modified: 21 Nov 2024

    The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9488

    Last Modified: 21 Nov 2024

    The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9487

    Last Modified: 21 Nov 2024

    The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9486

    Last Modified: 21 Nov 2024

    The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9485

    Last Modified: 21 Nov 2024

    The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9484

    Last Modified: 21 Nov 2024

    The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9483

    Last Modified: 21 Nov 2024

    The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9482

    Last Modified: 21 Nov 2024

    The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.8
    High

    CVE-2019-14570

    Last Modified: 21 Nov 2024

    Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2015-9481

    Last Modified: 21 Nov 2024

    The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

    Published: 11 Oct 2019
    7.8
    High

    CVE-2019-14569

    Last Modified: 21 Nov 2024

    Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

    Published: 11 Oct 2019
    7.8
    High

    CVE-2019-11167

    Last Modified: 21 Nov 2024

    Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Oct 2019
    7.8
    High

    CVE-2019-11120

    Last Modified: 21 Nov 2024

    Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2019-6335

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified with Samsung Laser Printers. This vulnerability could potentially be exploited to create a denial of service.

    Published: 11 Oct 2019
    9.8
    Critical

    CVE-2019-17059

    Last Modified: 21 Nov 2024

    A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.

    Published: 11 Oct 2019
    5.3
    Medium

    CVE-2019-17503

    Last Modified: 21 Nov 2024

    An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REGISTER.cmd (aka /osm_tiles/REGISTER.cmd) directly: it contains sensitive information about the database through the SQL queries within this batch file. This file exposes SQL database information such as database version, table name, column name, etc.

    Published: 11 Oct 2019
    6.1
    Medium

    CVE-2019-17504

    Last Modified: 21 Nov 2024

    An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script via the /osm/report/ password parameter.

    Published: 11 Oct 2019
    6.7
    Medium

    CVE-2019-6333

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system service.

    Published: 11 Oct 2019
    6.7
    Medium

    CVE-2019-14510

    Last Modified: 21 Nov 2024

    An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdminxxxxxxxxx (e.g., FSAdmin123456789) on the server that hosts the LAN Cache and all clients that are assigned to a LAN Cache. This account is placed into the local Administrators group of all clients assigned to the LAN Cache. When the assigned client is a Domain Controller, the FSAdminxxxxxxxxx account is created as a domain account and automatically added as a member of the domain BUILTIN\Administrators group. Using the well known Pass-the-Hash techniques, an attacker can use the same FSAdminxxxxxxxxx hash from any LAN Cache client and pass this to a Domain Controller, providing administrative rights to the attacker on any Domain Controller. (Local account Pass-the-Hash mitigations do not protect domain accounts.)

    Published: 11 Oct 2019
    7.5
    High

    CVE-2010-5334

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

    Published: 11 Oct 2019
    7.5
    High

    CVE-2010-5335

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

    Published: 11 Oct 2019
    6.1
    Medium

    CVE-2010-5336

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.

    Published: 11 Oct 2019
    6.1
    Medium

    CVE-2010-5337

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.

    Published: 11 Oct 2019
    6.1
    Medium

    CVE-2010-5338

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.

    Published: 11 Oct 2019
    6.1
    Medium

    CVE-2010-5339

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.

    Published: 11 Oct 2019
    6.1
    Medium

    CVE-2010-5340

    Last Modified: 21 Nov 2024

    IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.

    Published: 11 Oct 2019
    8.8
    High

    CVE-2019-17499

    Last Modified: 21 Nov 2024

    The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execute OS commands as root via shell metacharacters in the Target_IP parameter.

    Published: 11 Oct 2019
    5.5
    Medium

    CVE-2019-14858

    Last Modified: 21 Nov 2024

    A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.

    Published: 11 Oct 2019
    5.3
    Medium

    CVE-2019-17594

    Last Modified: 21 Nov 2024

    There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

    Published: 11 Oct 2019
    4.9
    Medium

    CVE-2019-14838

    Last Modified: 21 Nov 2024

    A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

    Published: 11 Oct 2019
    5.4
    Medium

    CVE-2019-17595

    Last Modified: 21 Nov 2024

    There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

    Published: 11 Oct 2019
    6.5
    Medium

    CVE-2019-17497

    Last Modified: 27 Nov 2024

    Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17496

    Last Modified: 21 Nov 2024

    Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-17495

    Last Modified: 21 Nov 2024

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17488

    Last Modified: 21 Nov 2024

    b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17489

    Last Modified: 21 Nov 2024

    Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/polygon/problem/update or web/admin/problem/create.

    Published: 10 Oct 2019
    8.8
    High

    CVE-2019-17490

    Last Modified: 21 Nov 2024

    app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload, as demonstrated by PHP code (with a .php filename but the image/png content type) to the web/polygon/problem/tests URI.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17491

    Last Modified: 21 Nov 2024

    Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web/polygon/problem/update.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17493

    Last Modified: 21 Nov 2024

    Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or web/polygon/problem/update.

    Published: 10 Oct 2019
    6.1
    Medium

    CVE-2019-17494

    Last Modified: 21 Nov 2024

    laravel-bjyblog 6.1.1 has XSS via a crafted URL.

    Published: 10 Oct 2019
    7.8
    High

    CVE-2019-9534

    Last Modified: 21 Nov 2024

    The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware that could be used to intercept or modify traffic, spoof or intercept GPS traffic, exfiltrate private data, hide a backdoor, or cause a denial-of-service.

    Published: 10 Oct 2019
    9.8
    Critical

    CVE-2019-9533

    Last Modified: 21 Nov 2024

    The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.

    Published: 10 Oct 2019