CVE Feed

    Dashboard / CVE

    4.1
    Medium

    CVE-2019-16089

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.

    Published: 6 Sept 2019
    5.9
    Medium

    CVE-2019-25013

    Last Modified: 9 Jun 2025

    The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

    Published: 6 Sept 2019
    7.8
    High

    CVE-2019-2181

    Last Modified: 21 Nov 2024

    In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2108

    Last Modified: 21 Nov 2024

    In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-9254

    Last Modified: 21 Nov 2024

    In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    5.5
    Medium

    CVE-2019-2124

    Last Modified: 21 Nov 2024

    In ComposeActivityEmailExternal of ComposeActivityEmailExternal.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible way to silently attach files to an email due to a confused deputy. This could lead to local information disclosure.

    Published: 5 Sept 2019
    5.5
    Medium

    CVE-2019-2180

    Last Modified: 21 Nov 2024

    In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure from the printer service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    5.5
    Medium

    CVE-2019-2179

    Last Modified: 21 Nov 2024

    In NDEF_MsgValidate of ndef_utils in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2178

    Last Modified: 21 Nov 2024

    In rw_t4t_sm_read_ndef of rw_t4t in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the NFC service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2115

    Last Modified: 21 Nov 2024

    In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-2177

    Last Modified: 21 Nov 2024

    In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2176

    Last Modified: 21 Nov 2024

    In ihevcd_parse_buffering_period_sei of ihevcd_parse_headers.c in Android 8.0, 8.1 and 9, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Sept 2019
    5.5
    Medium

    CVE-2019-2103

    Last Modified: 21 Nov 2024

    In Google Assistant in Android 9, there is a possible permissions bypass that allows the Assistant to take a screenshot of apps with FLAG_SECURE. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2175

    Last Modified: 21 Nov 2024

    In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2174

    Last Modified: 21 Nov 2024

    In SensorManager::assertStateLocked of SensorManager.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    7.8
    High

    CVE-2019-2123

    Last Modified: 21 Nov 2024

    In execTransact of Binder.java in Android 7.1.1, 7.1.2, 8.0, 8.1, and 9, there is a possible local execution of arbitrary code in a privileged process due to a memory overwrite. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 5 Sept 2019
    9.8
    Critical

    CVE-2019-14222

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated, remote attacker could authenticate to Alfresco's Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g., OS type, system file locations, Java version, Solr version, etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco's Solr Web Admin Interface.

    Published: 5 Sept 2019
    7.2
    High

    CVE-2019-14224

    Last Modified: 21 Nov 2024

    An issue was discovered in Alfresco Community Edition 5.2 201707. By leveraging multiple components in the Alfresco Software applications, an exploit chain was observed that allows an attacker to achieve remote code execution on the victim machine. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-15029

    Last Modified: 21 Nov 2024

    FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database). To trigger the command, one needs to call the services.php file via a GET request with the service id followed by the parameter a=start to execute the stored command.

    Published: 5 Sept 2019
    7.5
    High

    CVE-2019-11380

    Last Modified: 21 Nov 2024

    The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage.

    Published: 5 Sept 2019
    5.9
    Medium

    CVE-2019-10753

    Last Modified: 21 Nov 2024

    In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts that were produced. In case that any of these artifacts were compromised, any developers using these could be altered. **Note:** In order to validate that this artifact was not compromised, the maintainer would need to confirm that none of the artifacts published to the registry were not altered with. Until this happens, we can not guarantee that this artifact was not compromised even though the probability that this happened is low.

    Published: 5 Sept 2019
    5.5
    Medium

    CVE-2019-14339

    Last Modified: 21 Nov 2024

    The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capability.data data access. This allows an attacker's malicious application to obtain sensitive information including factory passwords for the administrator web interface and WPA2-PSK key.

    Published: 5 Sept 2019
    6.1
    Medium

    CVE-2019-15848

    Last Modified: 21 Nov 2024

    JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.

    Published: 5 Sept 2019
    5.3
    Medium

    CVE-2019-15944

    Last Modified: 21 Nov 2024

    In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-15952

    Last Modified: 21 Nov 2024

    An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-15953

    Last Modified: 21 Nov 2024

    An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal privilege escalation.

    Published: 5 Sept 2019
    9.9
    Critical

    CVE-2019-15954

    Last Modified: 21 Nov 2024

    An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

    Published: 5 Sept 2019
    6.5
    Medium

    CVE-2019-15955

    Last Modified: 21 Nov 2024

    An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin, then it is possible to brute force it with O(n)=2n instead of O(n)=n^x complexity, and steal the admin password.

    Published: 5 Sept 2019
    9.8
    Critical

    CVE-2019-13188

    Last Modified: 21 Nov 2024

    In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.

    Published: 5 Sept 2019
    5.3
    Medium

    CVE-2019-14278

    Last Modified: 21 Nov 2024

    In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.

    Published: 5 Sept 2019
    7.5
    High

    CVE-2019-13191

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /ApplicationEngine/Search/Refine/Set page.

    Published: 5 Sept 2019
    9.8
    Critical

    CVE-2019-13187

    Last Modified: 21 Nov 2024

    The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file upload vulnerability in content.fileupload.php and content.imageupload.php.

    Published: 5 Sept 2019
    4.9
    Medium

    CVE-2019-13349

    Last Modified: 21 Nov 2024

    In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.

    Published: 5 Sept 2019
    6.5
    Medium

    CVE-2019-5070

    Last Modified: 21 Nov 2024

    An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-5069

    Last Modified: 21 Nov 2024

    A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-15949

    Last Modified: 6 Nov 2025

    Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is executed as root via a passwordless sudo entry; the script executes check_plugin, which is owned by the nagios user. A user logged into Nagios XI with permissions to modify plugins, or the nagios user on the server, can modify the check_plugin executable and insert malicious commands to execute as root.

    Published: 5 Sept 2019
    5.3
    Medium

    CVE-2019-13190

    Last Modified: 21 Nov 2024

    In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.

    Published: 5 Sept 2019
    6.5
    Medium

    CVE-2019-13361

    Last Modified: 21 Nov 2024

    Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.

    Published: 5 Sept 2019
    7.5
    High

    CVE-2019-15947

    Last Modified: 21 Nov 2024

    In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their private keys, via a grep "6231 0500" command.

    Published: 5 Sept 2019
    5.3
    Medium

    CVE-2019-5065

    Last Modified: 21 Nov 2024

    An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. A specially crafted packet can cause an unterminated strncpy, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.

    Published: 5 Sept 2019
    6.4
    Medium

    CVE-2019-15946

    Last Modified: 21 Nov 2024

    OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.

    Published: 5 Sept 2019
    6.4
    Medium

    CVE-2019-15945

    Last Modified: 21 Nov 2024

    OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.

    Published: 5 Sept 2019
    8.8
    High

    CVE-2019-15942

    Last Modified: 21 Nov 2024

    FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffer.

    Published: 5 Sept 2019
    9.8
    Critical

    CVE-2018-11569

    Last Modified: 21 Nov 2024

    Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.

    Published: 5 Sept 2019
    7.5
    High

    CVE-2019-12223

    Last Modified: 21 Nov 2024

    An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before 2019-05-03. A system crash and reboot can be achieved by submitting a long username in excess of 117 characters. The username triggers a buffer overflow in the main process controlling operation of the DVR system, rendering services unavailable during the reboot operation. A repeated attack affects availability as long as the attacker has network access to the device.

    Published: 5 Sept 2019
    7.5
    High

    CVE-2019-4321

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 161201.

    Published: 5 Sept 2019
    6.1
    Medium

    CVE-2019-4186

    Last Modified: 21 Nov 2024

    IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-force ID: 158976.

    Published: 5 Sept 2019
    5.4
    Medium

    CVE-2019-4149

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow V18.0.0.0 through V18.0.0.2 and IBM Business Process Manager V8.6.0.0 through V8.6.0.0 Cumulative Fix 2018.03, V8.5.7.0 through V8.5.7.0 Cumulative Fix 2017.06, and V8.5.6.0 through V8.5.6.0 CF2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158415.

    Published: 5 Sept 2019
    9.8
    Critical

    CVE-2019-15937

    Last Modified: 21 Nov 2024

    Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.

    Published: 5 Sept 2019
    9.8
    Critical

    CVE-2019-15938

    Last Modified: 21 Nov 2024

    Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.

    Published: 5 Sept 2019