CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-16300

    Last Modified: 3 Dec 2025

    The BGP parser in tcpdump before 4.9.3 allows stack consumption in print-bgp.c:bgp_attr_print() because of unlimited recursion.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-16230

    Last Modified: 3 Dec 2025

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).

    Published: 2 Oct 2019
    7
    High

    CVE-2018-14879

    Last Modified: 3 Dec 2025

    The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14470

    Last Modified: 3 Dec 2025

    The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14880

    Last Modified: 21 Nov 2024

    The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14469

    Last Modified: 21 Nov 2024

    The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14466

    Last Modified: 21 Nov 2024

    The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2018-10103

    Last Modified: 21 Nov 2024

    tcpdump before 4.9.3 mishandles the printing of SMB data (issue 1 of 2).

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14467

    Last Modified: 3 Dec 2025

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14882

    Last Modified: 3 Dec 2025

    The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-16227

    Last Modified: 21 Nov 2024

    The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-16229

    Last Modified: 21 Nov 2024

    The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-10215

    Last Modified: 21 Nov 2024

    Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14881

    Last Modified: 3 Dec 2025

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-14857

    Last Modified: 21 Nov 2024

    A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.

    Published: 2 Oct 2019
    7.3
    High

    CVE-2019-3834

    Last Modified: 21 Nov 2024

    It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14463

    Last Modified: 21 Nov 2024

    The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-16228

    Last Modified: 3 Dec 2025

    The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

    Published: 2 Oct 2019
    9.8
    Critical

    CVE-2018-10105

    Last Modified: 21 Nov 2024

    tcpdump before 4.9.3 mishandles the printing of SMB data (issue 2 of 2).

    Published: 2 Oct 2019
    7.5
    High

    CVE-2018-14464

    Last Modified: 21 Nov 2024

    The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

    Published: 2 Oct 2019
    6.1
    Medium

    CVE-2019-8290

    Last Modified: 21 Nov 2024

    Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by posting directly to sent_register.php allowing special characters to be included and an XSS payload to be injected.

    Published: 1 Oct 2019
    5.4
    Medium

    CVE-2019-8288

    Last Modified: 21 Nov 2024

    Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.

    Published: 1 Oct 2019
    5.4
    Medium

    CVE-2019-8289

    Last Modified: 21 Nov 2024

    Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable

    Published: 1 Oct 2019
    7.5
    High

    CVE-2019-8291

    Last Modified: 21 Nov 2024

    Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.

    Published: 1 Oct 2019
    5.3
    Medium

    CVE-2019-8292

    Last Modified: 21 Nov 2024

    Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.

    Published: 1 Oct 2019
    6.1
    Medium

    CVE-2019-15041

    Last Modified: 21 Nov 2024

    JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.

    Published: 1 Oct 2019
    4.9
    Medium

    CVE-2019-15035

    Last Modified: 21 Nov 2024

    An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially confidential server-level data. The issue was fixed in TeamCity 2018.2.5 and 2019.1.

    Published: 1 Oct 2019
    6.5
    Medium

    CVE-2019-17073

    Last Modified: 21 Nov 2024

    emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tpl=../ directory traversal.

    Published: 1 Oct 2019
    5.4
    Medium

    CVE-2019-17074

    Last Modified: 21 Nov 2024

    An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.

    Published: 1 Oct 2019
    6.5
    Medium

    CVE-2019-7618

    Last Modified: 21 Nov 2024

    A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is possible to read arbitrary files from the local filesystem of the Kibana instance running Code with the permission of the Kibana system user.

    Published: 1 Oct 2019
    9.8
    Critical

    CVE-2019-17067

    Last Modified: 21 Nov 2024

    PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.

    Published: 1 Oct 2019
    7.5
    High

    CVE-2019-17068

    Last Modified: 21 Nov 2024

    PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected by malicious clipboard content.

    Published: 1 Oct 2019
    6.1
    Medium

    CVE-2019-14961

    Last Modified: 21 Nov 2024

    JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.

    Published: 1 Oct 2019
    7.5
    High

    CVE-2019-15042

    Last Modified: 21 Nov 2024

    An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.

    Published: 1 Oct 2019
    7.8
    High

    CVE-2019-14960

    Last Modified: 21 Nov 2024

    JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.

    Published: 1 Oct 2019
    5.3
    Medium

    CVE-2019-14955

    Last Modified: 21 Nov 2024

    In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no password expiration policy was implemented.

    Published: 1 Oct 2019
    6.1
    Medium

    CVE-2019-14953

    Last Modified: 21 Nov 2024

    JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox browser.

    Published: 1 Oct 2019
    7.5
    High

    CVE-2019-15038

    Last Modified: 21 Nov 2024

    An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP headers. The issue was fixed in TeamCity 2019.1.

    Published: 1 Oct 2019
    5.3
    Medium

    CVE-2019-14957

    Last Modified: 21 Nov 2024

    The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. This xml file could be synchronized to a publicly accessible GitHub repository.

    Published: 1 Oct 2019
    5.5
    Medium

    CVE-2019-17064

    Last Modified: 21 Nov 2024

    Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.

    Published: 1 Oct 2019
    5.5
    Medium

    CVE-2019-17063

    Last Modified: 21 Nov 2024

    In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.

    Published: 1 Oct 2019
    5.4
    Medium

    CVE-2019-4497

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164118.

    Published: 1 Oct 2019
    5.4
    Medium

    CVE-2019-4495

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164116.

    Published: 1 Oct 2019
    5.4
    Medium

    CVE-2019-4494

    Last Modified: 21 Nov 2024

    IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164115.

    Published: 1 Oct 2019
    5.3
    Medium

    CVE-2019-4246

    Last Modified: 21 Nov 2024

    IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in further attacks against the system. IBM X-Force ID: 159521.

    Published: 1 Oct 2019
    4.3
    Medium

    CVE-2019-11275

    Last Modified: 21 Nov 2024

    Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x prior to 668.0.21, versions 669.0.x prior to 669.0.13, and versions 670.0.x prior to 670.0.7, contain a vulnerability where a remote authenticated user can create an app with a name such that a csv program can interpret into a formula and gets executed. The malicious user can possibly gain access to a usage report that requires a higher privilege.

    Published: 1 Oct 2019
    3.3
    Low

    CVE-2019-10433

    Last Modified: 21 Nov 2024

    Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 1 Oct 2019
    7.5
    High

    CVE-2019-10435

    Last Modified: 21 Nov 2024

    Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

    Published: 1 Oct 2019
    7.5
    High

    CVE-2019-10434

    Last Modified: 21 Nov 2024

    Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

    Published: 1 Oct 2019
    6.1
    Medium

    CVE-2019-14952

    Last Modified: 21 Nov 2024

    JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles.

    Published: 1 Oct 2019