CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-13527

    Last Modified: 17 Dec 2024

    In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that has not been initialized.

    Published: 24 Sept 2019
    9.8
    Critical

    CVE-2019-16759

    Last Modified: 7 Nov 2025

    vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

    Published: 24 Sept 2019
    9.8
    Critical

    CVE-2019-16724

    Last Modified: 21 Nov 2024

    File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.

    Published: 24 Sept 2019
    6.5
    Medium

    CVE-2019-14220

    Last Modified: 21 Nov 2024

    An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs Android running in a virtual machine (VM) to enable Android apps to run on Windows or MacOS. Bug is in a local arbitrary file read through a system service call. The impacted method runs with System admin privilege and if given the file name as parameter returns you the content of file. A malicious app using the affected method can then read the content of any system file which it is not authorized to read

    Published: 24 Sept 2019
    6.1
    Medium

    CVE-2019-16725

    Last Modified: 21 Nov 2024

    In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.

    Published: 24 Sept 2019
    9.8
    Critical

    CVE-2019-5505

    Last Modified: 21 Nov 2024

    ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.

    Published: 24 Sept 2019
    9.8
    Critical

    CVE-2019-5504

    Last Modified: 21 Nov 2024

    ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.

    Published: 24 Sept 2019
    9.1
    Critical

    CVE-2019-16410

    Last Modified: 21 Nov 2024

    An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a lack of header_len checking.

    Published: 24 Sept 2019
    9.8
    Critical

    CVE-2019-16411

    Last Modified: 21 Nov 2024

    An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a memory region that is not allocated. There is a check for o->len < 5 (corresponding to 2 bytes of header and 3 bytes of data). Then, "flag = *(o->data + 3)" places one beyond the 3 bytes, because the code should have been "flag = *(o->data + 1)" instead.

    Published: 24 Sept 2019
    9.1
    Critical

    CVE-2019-15699

    Last Modified: 21 Nov 2024

    An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

    Published: 24 Sept 2019
    6.6
    Medium

    CVE-2019-14239

    Last Modified: 21 Nov 2024

    On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register.

    Published: 24 Sept 2019
    6.6
    Medium

    CVE-2019-14238

    Last Modified: 21 Nov 2024

    On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug probe via the Instruction Tightly Coupled Memory (ITCM) bus.

    Published: 24 Sept 2019
    7.5
    High

    CVE-2019-16754

    Last Modified: 21 Nov 2024

    RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attacker to crash a network node running RIOT. This requires spoofing an MQTT server response. To do so, the attacker needs to know the MQTT MsgID of a pending MQTT protocol message and the ephemeral port used by RIOT's MQTT implementation. Additionally, the server IP address is required for spoofing the packet.

    Published: 24 Sept 2019
    6.1
    Medium

    CVE-2019-16751

    Last Modified: 21 Nov 2024

    An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cross Site Scripting (XSS) through the message parameter. Unauthenticated attackers can craft a URL that executes a malicious JavaScript payload in the victim's browser. This affects the fallback_render method in the omniauth callbacks controller.

    Published: 24 Sept 2019
    7.5
    High

    CVE-2019-14753

    Last Modified: 21 Nov 2024

    SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow

    Published: 24 Sept 2019
    6.7
    Medium

    CVE-2019-3726

    Last Modified: 21 Nov 2024

    An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms. The vulnerability is limited to the DUP framework during the time window when a DUP is being executed by an administrator. During this time window, a locally authenticated low privilege malicious user potentially could exploit this vulnerability by tricking an administrator into running a trusted binary, causing it to load a malicious DLL and allowing the attacker to execute arbitrary code on the victim system. The vulnerability does not affect the actual binary payload that the DUP delivers.

    Published: 24 Sept 2019
    9.4
    Critical

    CVE-2019-16383

    Last Modified: 21 Nov 2024

    MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 allows an unauthenticated attacker to gain unauthorized access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, or may be able to alter the database via the REST API, aka SQL Injection.

    Published: 24 Sept 2019
    7.8
    High

    CVE-2019-13355

    Last Modified: 21 Nov 2024

    In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.exe allows local attackers to hijack dotnetproxy.exe, which leads to privilege escalation when the ccSchedulerSVC service runs the executable.

    Published: 24 Sept 2019
    7.8
    High

    CVE-2019-13356

    Last Modified: 21 Nov 2024

    In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT.exe allows local attackers to hijack bdcore.dll, which leads to privilege escalation when the AMRT service loads the DLL.

    Published: 24 Sept 2019
    7.8
    High

    CVE-2019-13357

    Last Modified: 21 Nov 2024

    In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allows local attackers to hijack ccGUIFrm.dll, which leads to code execution. SYSTEM-level code execution can be achieved when the ccSchedulerSVC service runs the affected executable.

    Published: 24 Sept 2019
    5.5
    Medium

    CVE-2019-4566

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 166627.

    Published: 24 Sept 2019
    6.5
    Medium

    CVE-2019-4515

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 165137.

    Published: 24 Sept 2019
    6.1
    Medium

    CVE-2018-9090

    Last Modified: 21 Nov 2024

    CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to later be configured by Tectonic administrators. An attacker can insert an XSS payload into the dashboards.

    Published: 24 Sept 2019
    9.8
    Critical

    CVE-2019-16748

    Last Modified: 21 Nov 2024

    In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there is a one-byte heap-based buffer over-read in CheckCertSignature_ex in wolfcrypt/src/asn.c.

    Published: 24 Sept 2019
    7.8
    High

    CVE-2019-16729

    Last Modified: 21 Nov 2024

    pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.

    Published: 24 Sept 2019
    6.1
    Medium

    CVE-2019-16728

    Last Modified: 21 Nov 2024

    DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16794

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16796

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16798

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16799

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16802

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16803

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16805

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16806

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16808

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16810

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16812

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16813

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16814

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16817

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16819

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16822

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16823

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16824

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16825

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16826

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16827

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16828

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16832

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019
    —
    Unknown

    CVE-2019-16839

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.

    Published: 24 Sept 2019