CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-2067

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-116114402

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-2068

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117099943

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-2070

    Last Modified: 21 Nov 2024

    In libxaac, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117883804

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-2071

    Last Modified: 21 Nov 2024

    In libxaac there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-117216549

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-11755

    Last Modified: 21 Nov 2024

    A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. Previous versions had only suppressed showing a digital signature for messages with an outer multipart/signed layer. This vulnerability affects Thunderbird < 68.1.1.

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-16924

    Last Modified: 21 Nov 2024

    The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network) to take control of the lock.

    Published: 27 Sept 2019
    —
    Unknown

    CVE-2019-11722

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Sept 2019
    6.1
    Medium

    CVE-2019-16923

    Last Modified: 21 Nov 2024

    kkcms 1.3 has jx.php?url= XSS.

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-8075

    Last Modified: 21 Nov 2024

    Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-8074

    Last Modified: 21 Nov 2024

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Successful exploitation could lead to Access Control Bypass in the context of the current user.

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-8073

    Last Modified: 21 Nov 2024

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-8072

    Last Modified: 21 Nov 2024

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

    Published: 27 Sept 2019
    5.3
    Medium

    CVE-2019-16922

    Last Modified: 21 Nov 2024

    SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.

    Published: 27 Sept 2019
    7.8
    High

    CVE-2018-19592

    Last Modified: 21 Nov 2024

    The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-4141

    Last Modified: 21 Nov 2024

    IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code. IBM X-Force ID: 158337.

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-13376

    Last Modified: 21 Nov 2024

    phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote Avatar feature. The CSRF Token Hijacking leads to stored XSS

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-16920

    Last Modified: 7 Nov 2025

    Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead to common injection. An attacker who successfully triggers the command injection could achieve full system compromise. Later, it was independently found that these are also affected: DIR-855L, DAP-1533, DIR-862L, DIR-615, DIR-835, and DIR-825.

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-16902

    Last Modified: 21 Nov 2024

    In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-16928

    Last Modified: 7 Nov 2025

    Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-based buffer overflow in string_vformat in string.c involving a long EHLO command.

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-16943

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.

    Published: 27 Sept 2019
    7.8
    High

    CVE-2019-9853

    Last Modified: 21 Nov 2024

    LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution This issue affects: LibreOffice 6.2 series versions prior to 6.2.7; LibreOffice 6.3 series versions prior to 6.3.1.

    Published: 27 Sept 2019
    7.5
    High

    CVE-2019-16921

    Last Modified: 21 Nov 2024

    In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813.

    Published: 27 Sept 2019
    9.8
    Critical

    CVE-2019-16942

    Last Modified: 21 Nov 2024

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9338

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111762686

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9335

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112328051

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9336

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112326322

    Published: 27 Sept 2019
    6.5
    Medium

    CVE-2019-9337

    Last Modified: 21 Nov 2024

    In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112204376

    Published: 27 Sept 2019
    8.8
    High

    CVE-2019-11279

    Last Modified: 21 Nov 2024

    CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

    Published: 26 Sept 2019
    8.8
    High

    CVE-2019-11278

    Last Modified: 21 Nov 2024

    CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.

    Published: 26 Sept 2019
    5.3
    Medium

    CVE-2019-15891

    Last Modified: 21 Nov 2024

    An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-15862

    Last Modified: 21 Nov 2024

    An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2019-12562

    Last Modified: 21 Nov 2024

    Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.

    Published: 26 Sept 2019
    8.8
    High

    CVE-2019-16667

    Last Modified: 21 Nov 2024

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces a "CSRF token expired" error and a Try Again button when a CSRF token is missing.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2019-16914

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.

    Published: 26 Sept 2019
    9.8
    Critical

    CVE-2019-16915

    Last Modified: 21 Nov 2024

    An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

    Published: 26 Sept 2019
    4.8
    Medium

    CVE-2019-16524

    Last Modified: 21 Nov 2024

    The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

    Published: 26 Sept 2019
    9.8
    Critical

    CVE-2019-16755

    Last Modified: 21 Nov 2024

    BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-6161

    Last Modified: 21 Nov 2024

    An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs.

    Published: 26 Sept 2019
    7.5
    High

    CVE-2019-6175

    Last Modified: 21 Nov 2024

    A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations.

    Published: 26 Sept 2019
    7.8
    High

    CVE-2019-12091

    Last Modified: 21 Nov 2024

    The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling function in this service suffers from command injection vulnerability. Local users can use this vulnerability to execute code with NT\SYSTEM privilege.

    Published: 26 Sept 2019
    7.8
    High

    CVE-2019-10882

    Last Modified: 21 Nov 2024

    The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling function in this service suffers from a stack based buffer overflow in "doHandshakefromServer" function. Local users can use this vulnerability to trigger a crash of the service and potentially cause additional impact on the system.

    Published: 26 Sept 2019
    6.5
    Medium

    CVE-2019-4378

    Last Modified: 21 Nov 2024

    IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 command server is vulnerable to a denial of service attack caused by an authenticated and authorized user using specially crafted PCF messages. IBM X-Force ID: 162084.

    Published: 26 Sept 2019
    5.3
    Medium

    CVE-2019-4262

    Last Modified: 21 Nov 2024

    IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the QRadar system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 160014.

    Published: 26 Sept 2019
    —
    Unknown

    CVE-2019-16895

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16894. Reason: This candidate is a reservation duplicate of CVE-2019-16894. Notes: All CVE users should reference CVE-2019-16894 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Sept 2019
    5.3
    Medium

    CVE-2019-16409

    Last Modified: 21 Nov 2024

    In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users who upgrade from SilverStripe 3.x to 4.x and had Versioned Files installed have no further need for this module, because the 4.x release has built-in versioning. However, nothing in the upgrade process automates the destruction of these insecure artefacts, nor alerts the user to the criticality of destruction.)

    Published: 26 Sept 2019
    9.8
    Critical

    CVE-2019-16894

    Last Modified: 21 Nov 2024

    download.php in inoERP 4.15 allows SQL injection through insecure deserialization.

    Published: 26 Sept 2019
    6.1
    Medium

    CVE-2019-16532

    Last Modified: 21 Nov 2024

    An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.

    Published: 26 Sept 2019
    5.3
    Medium

    CVE-2019-13523

    Last Modified: 21 Nov 2024

    In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance IP Cameras: HBD3PR2,H4D3PRV3,HED3PR3,H4D3PRV2,HBD3PR1,H4W8PR2,HBW8PR2,H2W2PC1M,H2W4PER3,H2W2PER3,HEW2PER3,HEW4PER3B,HBW2PER1,HEW4PER2,HEW4PER2B,HEW2PER2,H4W2PER2,HBW2PER2,H4W2PER3, and HPW2P1. Affected Performance Series NVRs: HEN08104,HEN08144,HEN081124,HEN16104,HEN16144,HEN16184,HEN16204,HEN162244,HEN16284,HEN16304,HEN16384,HEN32104,HEN321124,HEN32204,HEN32284,HEN322164,HEN32304, HEN32384,HEN323164,HEN64204,HEN64304,HEN643164,HEN643324,HEN643484,HEN04103,HEN04113,HEN04123,HEN08103,HEN08113,HEN08123,HEN08143,HEN16103,HEN16123,HEN16143,HEN16163,HEN04103L,HEN08103L,HEN16103L,HEN32103L.

    Published: 26 Sept 2019
    2.7
    Low

    CVE-2019-12617

    Last Modified: 21 Nov 2024

    In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pollution.

    Published: 26 Sept 2019
    5.4
    Medium

    CVE-2019-14272

    Last Modified: 21 Nov 2024

    In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.

    Published: 26 Sept 2019