CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2019-16234

    Last Modified: 21 Nov 2024

    drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

    Published: 9 Sept 2019
    5.9
    Medium

    CVE-2019-10214

    Last Modified: 21 Nov 2024

    The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

    Published: 9 Sept 2019
    7.5
    High

    CVE-2019-12401

    Last Modified: 21 Nov 2024

    Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs.

    Published: 9 Sept 2019
    9.8
    Critical

    CVE-2019-16140

    Last Modified: 21 Nov 2024

    An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion.

    Published: 9 Sept 2019
    6.1
    Medium

    CVE-2019-16117

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/models/Galleries.php.

    Published: 8 Sept 2019
    6.1
    Medium

    CVE-2019-16118

    Last Modified: 21 Nov 2024

    Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admin/controllers/Options.php.

    Published: 8 Sept 2019
    9.8
    Critical

    CVE-2019-16119

    Last Modified: 21 Nov 2024

    SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/controllers/Albumsgalleries.php album_id parameter.

    Published: 8 Sept 2019
    8.8
    High

    CVE-2019-16120

    Last Modified: 7 Feb 2025

    CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.

    Published: 8 Sept 2019
    7.8
    High

    CVE-2019-16115

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used by GfxAxialShading::getColor. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It allows an attacker to use a crafted PDF file to cause Denial of Service or possibly unspecified other impact.

    Published: 8 Sept 2019
    8.8
    High

    CVE-2019-16113

    Last Modified: 21 Nov 2024

    Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.

    Published: 8 Sept 2019
    5.3
    Medium

    CVE-2019-16109

    Last Modified: 21 Nov 2024

    An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank confirmation_token, if a database record has a blank value in the confirmation_token column. (However, there is no scenario within Devise itself in which such database records would exist.)

    Published: 8 Sept 2019
    8.8
    High

    CVE-2019-16099

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

    Published: 8 Sept 2019
    7.5
    High

    CVE-2019-16100

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source.

    Published: 8 Sept 2019
    5.3
    Medium

    CVE-2019-16101

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI.

    Published: 8 Sept 2019
    9.8
    Critical

    CVE-2019-16102

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.

    Published: 8 Sept 2019
    7.2
    High

    CVE-2019-16103

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell feature.

    Published: 8 Sept 2019
    6.1
    Medium

    CVE-2019-16104

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

    Published: 8 Sept 2019
    4.9
    Medium

    CVE-2019-16105

    Last Modified: 21 Nov 2024

    Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.

    Published: 8 Sept 2019
    6.5
    Medium

    CVE-2019-16097

    Last Modified: 21 Nov 2024

    core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

    Published: 8 Sept 2019
    7.5
    High

    CVE-2016-10937

    Last Modified: 21 Nov 2024

    IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

    Published: 8 Sept 2019
    7.5
    High

    CVE-2019-16096

    Last Modified: 21 Nov 2024

    Kilo 0.0.1 has a heap-based buffer overflow because there is an integer overflow in a calculation involving the number of tabs in one row.

    Published: 8 Sept 2019
    7.5
    High

    CVE-2019-16091

    Last Modified: 21 Nov 2024

    Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.

    Published: 8 Sept 2019
    9.8
    Critical

    CVE-2019-16092

    Last Modified: 21 Nov 2024

    Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.

    Published: 8 Sept 2019
    9.8
    Critical

    CVE-2019-16093

    Last Modified: 21 Nov 2024

    Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.

    Published: 8 Sept 2019
    7.5
    High

    CVE-2019-16094

    Last Modified: 21 Nov 2024

    Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.

    Published: 8 Sept 2019
    7.5
    High

    CVE-2019-16095

    Last Modified: 21 Nov 2024

    Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.

    Published: 8 Sept 2019
    5.3
    Medium

    CVE-2019-16249

    Last Modified: 21 Nov 2024

    OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMeanNorm in modules/video/src/dis_flow.cpp.

    Published: 8 Sept 2019
    β€”
    Unknown

    CVE-2019-9457

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14634. Reason: This candidate is a reservation duplicate of CVE-2018-14634. Notes: All CVE users should reference CVE-2018-14634 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Sept 2019
    5.5
    Medium

    CVE-2019-16088

    Last Modified: 21 Nov 2024

    Xpdf 3.04 has a SIGSEGV in XRef::fetch in XRef.cc after many recursive calls to Catalog::countPageTree in Catalog.cc.

    Published: 6 Sept 2019
    6.5
    Medium

    CVE-2019-15128

    Last Modified: 21 Nov 2024

    iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.

    Published: 6 Sept 2019
    6.1
    Medium

    CVE-2018-11198

    Last Modified: 21 Nov 2024

    An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-10892

    Last Modified: 21 Nov 2024

    An issue was discovered in D-Link DIR-806 devices. There is a stack-based buffer overflow in function hnap_main at /htdocs/cgibin. The function will call sprintf without checking the length of strings in parameters given by HTTP header and can be controlled by users. And it finally leads to a stack-based buffer overflow via a special HTTP header.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-10891

    Last Modified: 9 Jan 2025

    An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the parameter that can be controlled by user, and finally allows remote attackers to execute arbitrary shell commands with a special HTTP header.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-11925

    Last Modified: 21 Nov 2024

    Insufficient boundary checks when processing the JPEG APP12 block marker in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-11926

    Last Modified: 21 Nov 2024

    Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2016-7398

    Last Modified: 21 Nov 2024

    A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-9855

    Last Modified: 21 Nov 2024

    LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added to block calling LibreLogo from script event handers. However a Windows 8.3 path equivalence handling flaw left LibreOffice vulnerable under Windows that a document could trigger executing LibreLogo via a Windows filename pseudonym. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-16060

    Last Modified: 21 Nov 2024

    The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected).

    Published: 6 Sept 2019
    8.8
    High

    CVE-2019-16059

    Last Modified: 21 Nov 2024

    Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/viewprofile via a crafted HTML page.

    Published: 6 Sept 2019
    7.5
    High

    CVE-2019-16058

    Last Modified: 21 Nov 2024

    An issue was discovered in the pam_p11 component 0.2.0 and 0.3.0 for OpenSC. If a smart card creates a signature with a length longer than 256 bytes, this triggers a buffer overflow. This may be the case for RSA keys with 4096 bits depending on the signature scheme.

    Published: 6 Sept 2019
    7.8
    High

    CVE-2018-18630

    Last Modified: 21 Nov 2024

    A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-15102

    Last Modified: 21 Nov 2024

    An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.

    Published: 6 Sept 2019
    6.1
    Medium

    CVE-2019-14223

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious website over any protocol the attacker desires (e.g.,http, https, ftp, smb, etc.).

    Published: 6 Sept 2019
    8.8
    High

    CVE-2019-13953

    Last Modified: 21 Nov 2024

    An exploitable authentication bypass vulnerability exists in the Bluetooth Low Energy (BLE) authentication module of YI M1 Mirrorless Camera V3.2-cn. An attacker can send a set of BLE commands to trigger this vulnerability, resulting in sensitive data leakage (e.g., personal photos). An attacker can also control the camera to record or take a picture after bypassing authentication.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-13656

    Last Modified: 21 Nov 2024

    An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code.

    Published: 6 Sept 2019
    7.8
    High

    CVE-2018-6240

    Last Modified: 21 Nov 2024

    NVIDIA Tegra contains a vulnerability in BootRom where a user with kernel level privileges can write an arbitrary value to an arbitrary physical address

    Published: 6 Sept 2019
    8.8
    High

    CVE-2019-13517

    Last Modified: 21 Nov 2024

    In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access privileges are not restricted in coordination with the expiration of access based on active directory user account changes when the device is joined to an AD domain.

    Published: 6 Sept 2019
    9.8
    Critical

    CVE-2019-15846

    Last Modified: 21 Nov 2024

    Exim before 4.92.2 allows remote attackers to execute arbitrary code as root via a trailing backslash.

    Published: 6 Sept 2019
    4.4
    Medium

    CVE-2019-15030

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector registers will be corrupted with the values from a different local Linux process because of a missing arch/powerpc/kernel/process.c check.

    Published: 6 Sept 2019
    7.8
    High

    CVE-2019-9854

    Last Modified: 21 Nov 2024

    LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed by employing a URL encoding attack to defeat the path verification step. However this protection could be bypassed by taking advantage of a flaw in how LibreOffice assembled the final script URL location directly from components of the passed in path as opposed to solely from the sanitized output of the path verification step. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.

    Published: 6 Sept 2019
    Items Per Page