CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2019-11251

    Last Modified: 21 Nov 2024

    The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp invocation. This could be used to allow an attacker to place a nefarious file using a symlink, outside of the destination tree.

    Published: 18 Sept 2019
    8.8
    High

    CVE-2019-13686

    Last Modified: 21 Nov 2024

    Use after free in offline mode in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Sept 2019
    8.8
    High

    CVE-2019-13687

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Sept 2019
    9.8
    Critical

    CVE-2020-12278

    Last Modified: 21 Nov 2024

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. path.c mishandles equivalent filenames that exist because of NTFS Alternate Data Streams. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1352.

    Published: 18 Sept 2019
    9.8
    Critical

    CVE-2020-12279

    Last Modified: 21 Nov 2024

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0. checkout.c mishandles equivalent filenames that exist because of NTFS short names. This may allow remote code execution when cloning a repository. This issue is similar to CVE-2019-1353.

    Published: 18 Sept 2019
    8.8
    High

    CVE-2019-13685

    Last Modified: 21 Nov 2024

    Use after free in sharing view in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Sept 2019
    7.5
    High

    CVE-2019-16413

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, which causes an i_size_read() infinite loop and denial of service on SMP systems.

    Published: 18 Sept 2019
    4.3
    Medium

    CVE-2019-11754

    Last Modified: 21 Nov 2024

    When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.

    Published: 18 Sept 2019
    8.8
    High

    CVE-2019-13688

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 77.0.3865.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Sept 2019
    7.8
    High

    CVE-2019-16395

    Last Modified: 21 Nov 2024

    GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.

    Published: 17 Sept 2019
    7.8
    High

    CVE-2019-16396

    Last Modified: 21 Nov 2024

    GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source code.

    Published: 17 Sept 2019
    9.8
    Critical

    CVE-2019-16199

    Last Modified: 21 Nov 2024

    eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with access to the web interface via an HTTP POST request to certain URLs related to the ReGa core process.

    Published: 17 Sept 2019
    6.5
    Medium

    CVE-2019-16391

    Last Modified: 21 Nov 2024

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

    Published: 17 Sept 2019
    6.1
    Medium

    CVE-2019-16392

    Last Modified: 21 Nov 2024

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

    Published: 17 Sept 2019
    6.1
    Medium

    CVE-2019-16393

    Last Modified: 21 Nov 2024

    SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

    Published: 17 Sept 2019
    5.3
    Medium

    CVE-2019-16394

    Last Modified: 21 Nov 2024

    SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-6828

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmware version prior to V3.10), Modicon Premium (all versions), and Modicon Quantum (all versions), which could cause a possible denial of service when reading specific coils and registers in the controller over Modbus.

    Published: 17 Sept 2019
    7.8
    High

    CVE-2019-6826

    Last Modified: 21 Nov 2024

    A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause arbitrary code execution on the system running SoMachine HVAC when a malicious DLL library is loaded by the product.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-6813

    Last Modified: 21 Nov 2024

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions) and Modicon M340 controller (all firmware versions), which could cause denial of service when truncated SNMP packets on port 161/UDP are received by the device.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-6811

    Last Modified: 21 Nov 2024

    An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.

    Published: 17 Sept 2019
    8.8
    High

    CVE-2019-6810

    Last Modified: 21 Nov 2024

    CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause the execution of commands by unauthorized users when using IEC 60870-5-104 protocol.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-6809

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (firmware versions prior to V3.10), Modicon Premium (all versions), Modicon Quantum (all versions), which could cause a possible denial of service when reading invalid data from the controller.

    Published: 17 Sept 2019
    9.8
    Critical

    CVE-2018-7820

    Last Modified: 21 Nov 2024

    A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintext when Remote Monitoring is enabled, and then disabled.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-6829

    Last Modified: 29 May 2026

    A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (firmware version prior to V3.10), which could cause a possible denial of service when writing to specific memory addresses in the controller over Modbus.

    Published: 17 Sept 2019
    6.5
    Medium

    CVE-2019-6833

    Last Modified: 30 Sept 2025

    A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all versions of - HMIGTO, HMISTO, XBTGH, HMIGTU, HMIGTUX, HMISCU, HMISTU, XBTGT, XBTGT, HMIGXO, HMIGXU), which could cause a temporary freeze of the HMI when a high rate of frames is received. When the attack stops, the buffered commands are processed by the HMI panel.

    Published: 17 Sept 2019
    8.3
    High

    CVE-2019-6832

    Last Modified: 21 Nov 2024

    A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions before 2.4.0 - formerly known as homeLYnk), which could cause loss of control when an attacker bypasses the authentication.

    Published: 17 Sept 2019
    8.6
    High

    CVE-2019-6831

    Last Modified: 21 Nov 2024

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions), which could cause disconnection of active connections when an unusually high number of IEC 60870- 5-104 packets are received by the module on port 2404/TCP.

    Published: 17 Sept 2019
    5.9
    Medium

    CVE-2019-6830

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a possible denial of service when sending an appropriately timed HTTP request to the controller.

    Published: 17 Sept 2019
    9.8
    Critical

    CVE-2019-6840

    Last Modified: 21 Nov 2024

    A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed.

    Published: 17 Sept 2019
    8.8
    High

    CVE-2019-6839

    Last Modified: 21 Nov 2024

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to upload a rogue file.

    Published: 17 Sept 2019
    6.5
    Medium

    CVE-2019-6838

    Last Modified: 21 Nov 2024

    A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow a user with low privileges to delete a critical file.

    Published: 17 Sept 2019
    9.1
    Critical

    CVE-2019-6837

    Last Modified: 21 Nov 2024

    A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could cause server configuration data to be exposed when an attacker modifies a URL.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-6836

    Last Modified: 21 Nov 2024

    A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow the file system to access the wrong file.

    Published: 17 Sept 2019
    5.4
    Medium

    CVE-2019-6835

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to inject client-side script when a user visits a web page.

    Published: 17 Sept 2019
    6.5
    Medium

    CVE-2019-4477

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line options. IBM X-Force ID: 163997.

    Published: 17 Sept 2019
    4.3
    Medium

    CVE-2019-4442

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the file system. An attacker could send a specially-crafted URL request to view arbitrary files on the system but not content. IBM X-Force ID: 163226.

    Published: 17 Sept 2019
    5.4
    Medium

    CVE-2019-4342

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 161421.

    Published: 17 Sept 2019
    3.5
    Low

    CVE-2019-4271

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter pollution vulnerability. IBM X-Force ID: 160243.

    Published: 17 Sept 2019
    5.4
    Medium

    CVE-2019-4270

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 160203.

    Published: 17 Sept 2019
    5.3
    Medium

    CVE-2019-4268

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 160201.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-4183

    Last Modified: 21 Nov 2024

    IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send specially crafted requests that would consume all available CPU and memory resources. IBM X-Force ID: 158973.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-4175

    Last Modified: 21 Nov 2024

    IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.

    Published: 17 Sept 2019
    3.7
    Low

    CVE-2019-4171

    Last Modified: 21 Nov 2024

    IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 158876.

    Published: 17 Sept 2019
    6.1
    Medium

    CVE-2019-4086

    Last Modified: 21 Nov 2024

    IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 157509.

    Published: 17 Sept 2019
    8.6
    High

    CVE-2019-13538

    Last Modified: 21 Nov 2024

    3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to display active library content without checking its validity, which may allow the contents of manipulated libraries to be displayed or executed. The issue also exists for source libraries, but 3S-Smart Software Solutions GmbH strongly recommends distributing compiled libraries only.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-11665

    Last Modified: 21 Nov 2024

    Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow sensitive data exposure.

    Published: 17 Sept 2019
    6.5
    Medium

    CVE-2019-13542

    Last Modified: 21 Nov 2024

    3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition.

    Published: 17 Sept 2019
    8.8
    High

    CVE-2019-11666

    Last Modified: 21 Nov 2024

    Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow insecure deserialization of untrusted data.

    Published: 17 Sept 2019
    7.5
    High

    CVE-2019-11667

    Last Modified: 21 Nov 2024

    Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerability could be exploited to allow unauthorized access to private data.

    Published: 17 Sept 2019
    8.8
    High

    CVE-2019-14821

    Last Modified: 21 Nov 2024

    An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.

    Published: 17 Sept 2019