CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-17450

    Last Modified: 21 Nov 2024

    find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.

    Published: 8 Oct 2019
    7.8
    High

    CVE-2019-18389

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.

    Published: 8 Oct 2019
    5.5
    Medium

    CVE-2019-18391

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.

    Published: 8 Oct 2019
    3.3
    Low

    CVE-2020-25675

    Last Modified: 21 Nov 2024

    In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer. Such issues could cause a negative impact to application availability or other problems related to undefined behavior, in cases where ImageMagick processes untrusted input data. The upstream patch introduces functionality to constrain the pixel offsets and prevent these issues. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 8 Oct 2019
    3.3
    Low

    CVE-2020-27765

    Last Modified: 21 Nov 2024

    A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 8 Oct 2019
    9.8
    Critical

    CVE-2019-17455

    Last Modified: 21 Nov 2024

    Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

    Published: 8 Oct 2019
    5.5
    Medium

    CVE-2019-18388

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.

    Published: 8 Oct 2019
    7.1
    High

    CVE-2019-18390

    Last Modified: 21 Nov 2024

    An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.

    Published: 8 Oct 2019
    3.8
    Low

    CVE-2019-18392

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 8 Oct 2019
    4.6
    Medium

    CVE-2019-19526

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.3.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/nfc/pn533/usb.c driver, aka CID-6af3aa57a098.

    Published: 8 Oct 2019
    5.5
    Medium

    CVE-2020-25676

    Last Modified: 21 Nov 2024

    In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstrained pixel offset calculations which were being used with the floor() function. These calculations produced undefined behavior in the form of out-of-range and integer overflows, as identified by UndefinedBehaviorSanitizer. These instances of undefined behavior could be triggered by an attacker who is able to supply a crafted input file to be processed by ImageMagick. These issues could impact application availability or potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

    Published: 8 Oct 2019
    7.5
    High

    CVE-2019-17232

    Last Modified: 21 Nov 2024

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import.

    Published: 7 Oct 2019
    6.1
    Medium

    CVE-2019-17233

    Last Modified: 21 Nov 2024

    Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.

    Published: 7 Oct 2019
    7.5
    High

    CVE-2019-13120

    Last Modified: 21 Nov 2024

    Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.

    Published: 7 Oct 2019
    7.8
    High

    CVE-2019-16913

    Last Modified: 21 Nov 2024

    PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders. In addition, the program installs a service called SecurityService that runs as LocalSystem. This allows any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a Trojan horse.

    Published: 7 Oct 2019
    6.1
    Medium

    CVE-2019-17239

    Last Modified: 21 Nov 2024

    includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.

    Published: 7 Oct 2019
    7.3
    High

    CVE-2019-3745

    Last Modified: 21 Nov 2024

    The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.

    Published: 7 Oct 2019
    6.8
    Medium

    CVE-2019-15894

    Last Modified: 21 Nov 2024

    An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3.x through 3.3.1. An attacker who uses fault injection to physically disrupt the ESP32 CPU can bypass the Secure Boot digest verification at startup, and boot unverified code from flash. The fault injection attack does not disable the Flash Encryption feature, so if the ESP32 is configured with the recommended combination of Secure Boot and Flash Encryption, then the impact is minimized. If the ESP32 is configured without Flash Encryption then successful fault injection allows arbitrary code execution. To protect devices with Flash Encryption and Secure Boot enabled against this attack, a firmware change must be made to permanently enable Flash Encryption in the field if it is not already permanently enabled.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17292

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17293

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17294

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the export function by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17295

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17296

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17297

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17298

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17299

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17300

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17301

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17302

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17303

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17304

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17305

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17306

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17307

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17308

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17309

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17310

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17311

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17312

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17313

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17314

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17315

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17316

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.

    Published: 7 Oct 2019
    7.2
    High

    CVE-2019-17317

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17318

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2019-17319

    Last Modified: 21 Nov 2024

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.

    Published: 7 Oct 2019
    6.5
    Medium

    CVE-2015-9456

    Last Modified: 21 Nov 2024

    The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.

    Published: 7 Oct 2019
    8.1
    High

    CVE-2015-9455

    Last Modified: 21 Nov 2024

    The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

    Published: 7 Oct 2019
    8.8
    High

    CVE-2015-9454

    Last Modified: 21 Nov 2024

    The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.

    Published: 7 Oct 2019
    6.1
    Medium

    CVE-2015-9453

    Last Modified: 21 Nov 2024

    The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.

    Published: 7 Oct 2019