CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2015-9382

    Last Modified: 21 Nov 2024

    FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation.

    Published: 3 Sept 2019
    4.4
    Medium

    CVE-2019-9245

    Last Modified: 21 Nov 2024

    In the Android kernel in the f2fs driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9248

    Last Modified: 21 Nov 2024

    In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9275

    Last Modified: 21 Nov 2024

    In the Android kernel in the mnh driver there is a use after free due to improper locking. This could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9436

    Last Modified: 21 Nov 2024

    In the Android kernel in the bootloader there is a possible secure boot bypass. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9451

    Last Modified: 21 Nov 2024

    In the Android kernel in the touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    9.3
    Critical

    CVE-2019-9812

    Last Modified: 25 Nov 2025

    Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered. This vulnerability affects Firefox ESR < 60.9, Firefox ESR < 68.1, and Firefox < 69.

    Published: 3 Sept 2019
    7.8
    High

    CVE-2019-2182

    Last Modified: 21 Nov 2024

    In the Android kernel in the kernel MMU code there is a possible execution path leaving some kernel text and rodata pages writable. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    8.1
    High

    CVE-2019-5849

    Last Modified: 21 Nov 2024

    Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 3 Sept 2019
    7.8
    High

    CVE-2019-9270

    Last Modified: 21 Nov 2024

    In the Android kernel in unifi and r8180 WiFi drivers there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.4
    Medium

    CVE-2019-9271

    Last Modified: 21 Nov 2024

    In the Android kernel in the mnh driver there is a race condition due to insufficient locking. This could lead to a use-after-free which could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9273

    Last Modified: 21 Nov 2024

    In the Android kernel in the synaptics_dsx_htc touchscreen driver there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9274

    Last Modified: 21 Nov 2024

    In the Android kernel in the mnh driver there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    7.8
    High

    CVE-2019-9345

    Last Modified: 21 Nov 2024

    In the Android kernel in sdcardfs there is a possible violation of the separation of data between profiles due to shared mapping of obb files. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9441

    Last Modified: 21 Nov 2024

    In the Android kernel in the mnh driver there is a possible out of bounds write due to improper input validation. This could lead to escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9442

    Last Modified: 21 Nov 2024

    In the Android kernel in the mnh driver there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System privileges required. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9443

    Last Modified: 21 Nov 2024

    In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege due to a set_fs() call without restoring the previous limit with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    4.4
    Medium

    CVE-2019-9444

    Last Modified: 21 Nov 2024

    In the Android kernel in sync debug fs driver there is a kernel pointer leak due to the usage of printf with %p. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9447

    Last Modified: 21 Nov 2024

    In the Android kernel in the FingerTipS touchscreen driver there is a possible use-after-free due to improper locking. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9448

    Last Modified: 21 Nov 2024

    In the Android kernel in the FingerTipS touchscreen driver there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    4.4
    Medium

    CVE-2019-9449

    Last Modified: 21 Nov 2024

    In the Android kernel in FingerTipS touchscreen driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.4
    Medium

    CVE-2019-9450

    Last Modified: 21 Nov 2024

    In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    4.4
    Medium

    CVE-2019-9453

    Last Modified: 21 Nov 2024

    In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    2.3
    Low

    CVE-2019-9455

    Last Modified: 21 Nov 2024

    In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.7
    Medium

    CVE-2019-9456

    Last Modified: 21 Nov 2024

    In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

    Published: 3 Sept 2019
    6.5
    Medium

    CVE-2015-9383

    Last Modified: 21 Nov 2024

    FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.

    Published: 3 Sept 2019
    6.5
    Medium

    CVE-2019-10197

    Last Modified: 21 Nov 2024

    A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when certain parameters were set in the samba configuration file. An unauthenticated attacker could use this flaw to escape the shared directory and access the contents of directories outside the share.

    Published: 3 Sept 2019
    8.8
    High

    CVE-2019-11735

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

    Published: 3 Sept 2019
    7
    High

    CVE-2019-11736

    Last Modified: 21 Nov 2024

    The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. <br>*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

    Published: 3 Sept 2019
    6.5
    Medium

    CVE-2019-11742

    Last Modified: 25 Nov 2025

    A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a &lt;canvas&gt; element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.

    Published: 3 Sept 2019
    7.5
    High

    CVE-2019-15847

    Last Modified: 21 Nov 2024

    The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

    Published: 2 Sept 2019
    7.5
    High

    CVE-2019-15630

    Last Modified: 21 Nov 2024

    Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.

    Published: 30 Aug 2019
    7.8
    High

    CVE-2019-12810

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .PSD file can cause an out of bounds write vulnerability resulting in code execution. By persuading a victim to open a specially-crafted .PSD file, an attacker could execute arbitrary code.

    Published: 30 Aug 2019
    6.1
    Medium

    CVE-2019-15842

    Last Modified: 21 Nov 2024

    The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.

    Published: 30 Aug 2019
    8.8
    High

    CVE-2019-15841

    Last Modified: 21 Nov 2024

    The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_fb_toggle_visibility.

    Published: 30 Aug 2019
    8.8
    High

    CVE-2019-15840

    Last Modified: 21 Nov 2024

    The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.

    Published: 30 Aug 2019
    7.5
    High

    CVE-2019-15839

    Last Modified: 24 Mar 2025

    The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.

    Published: 30 Aug 2019
    6.1
    Medium

    CVE-2019-15838

    Last Modified: 21 Nov 2024

    The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.

    Published: 30 Aug 2019
    5.4
    Medium

    CVE-2019-15837

    Last Modified: 21 Nov 2024

    The webp-express plugin before 0.14.8 for WordPress has stored XSS.

    Published: 30 Aug 2019
    5.4
    Medium

    CVE-2019-15836

    Last Modified: 21 Nov 2024

    The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.

    Published: 30 Aug 2019
    8.8
    High

    CVE-2019-15835

    Last Modified: 21 Nov 2024

    The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.

    Published: 30 Aug 2019
    8.8
    High

    CVE-2019-15834

    Last Modified: 21 Nov 2024

    The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11989

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11978

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11977

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11975

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11974

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11973

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11972

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019
    —
    Unknown

    CVE-2018-11969

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Aug 2019