CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-7968

    Last Modified: 21 Nov 2024

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15503

    Last Modified: 21 Nov 2024

    cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.

    Published: 26 Aug 2019
    6.5
    Medium

    CVE-2019-15515

    Last Modified: 21 Nov 2024

    Discourse 2.3.2 sends the CSRF token in the query string.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15533

    Last Modified: 21 Nov 2024

    XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.

    Published: 26 Aug 2019
    5.3
    Medium

    CVE-2017-18588

    Last Modified: 21 Nov 2024

    An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2018-20989

    Last Modified: 21 Nov 2024

    An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow and panic.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2017-18589

    Last Modified: 21 Nov 2024

    An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2018-20995

    Last Modified: 21 Nov 2024

    An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2018-20996

    Last Modified: 21 Nov 2024

    An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2018-20997

    Last Modified: 21 Nov 2024

    An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.

    Published: 26 Aug 2019
    10
    Critical

    CVE-2019-13020

    Last Modified: 21 Nov 2024

    The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve malicious content from a third-party attacker-controlled system. Second, arguably more severe, is the potential for an attacker to circumvent firewall controls, by proxying traffic, unauthenticated, into the internal network from the internet.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2018-20998

    Last Modified: 21 Nov 2024

    An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15542

    Last Modified: 21 Nov 2024

    An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15543

    Last Modified: 21 Nov 2024

    An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15544

    Last Modified: 21 Nov 2024

    An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15545

    Last Modified: 21 Nov 2024

    An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.

    Published: 26 Aug 2019
    8.8
    High

    CVE-2019-15642

    Last Modified: 21 Nov 2024

    rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command or modify any file on a server, which is why access to it must not be granted to un-trusted Webmin users."

    Published: 26 Aug 2019
    6.5
    Medium

    CVE-2019-15641

    Last Modified: 21 Nov 2024

    xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15546

    Last Modified: 21 Nov 2024

    An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.

    Published: 26 Aug 2019
    7.8
    High

    CVE-2019-12532

    Last Modified: 21 Nov 2024

    Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of privilege, or information disclosure via local access. This is a software vulnerability, not a firmware issue. Affected tools include: H2OFFT version 3.02~5.28, 100.00.00.00~100.00.08.23 and 200.00.00.01~200.00.00.05, H2OOAE before version 200.00.00.02, H2OSDE before version 200.00.00.07, H2OUVE before version 200.00.02.02, H2OPCM before version 100.00.06.00, H2OELV before version 100.00.02.08.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15547

    Last Modified: 21 Nov 2024

    An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15548

    Last Modified: 21 Nov 2024

    An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15549

    Last Modified: 21 Nov 2024

    An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplying a large value in a length field.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15640

    Last Modified: 21 Nov 2024

    Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15555

    Last Modified: 21 Nov 2024

    FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15557

    Last Modified: 21 Nov 2024

    XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15558

    Last Modified: 21 Nov 2024

    XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.

    Published: 26 Aug 2019
    8.1
    High

    CVE-2019-15637

    Last Modified: 21 Nov 2024

    Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15559

    Last Modified: 21 Nov 2024

    DianoxDragon Hawn before 2019-07-10 allows SQL injection.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15560

    Last Modified: 21 Nov 2024

    The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15563

    Last Modified: 21 Nov 2024

    Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15564

    Last Modified: 21 Nov 2024

    The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15565

    Last Modified: 21 Nov 2024

    The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15552

    Last Modified: 21 Nov 2024

    An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.

    Published: 26 Aug 2019
    8.2
    High

    CVE-2019-4513

    Last Modified: 21 Nov 2024

    IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 164555.

    Published: 26 Aug 2019
    7.8
    High

    CVE-2019-4448

    Last Modified: 21 Nov 2024

    IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.

    Published: 26 Aug 2019
    7.8
    High

    CVE-2019-4447

    Last Modified: 21 Nov 2024

    IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled location. When a crash is induced the trojan gdb command is executed. IBM X-Force ID: 163488.

    Published: 26 Aug 2019
    9.1
    Critical

    CVE-2019-4169

    Last Modified: 21 Nov 2024

    IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15551

    Last Modified: 21 Nov 2024

    An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15566

    Last Modified: 21 Nov 2024

    The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15554

    Last Modified: 21 Nov 2024

    An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15567

    Last Modified: 21 Nov 2024

    OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15553

    Last Modified: 21 Nov 2024

    An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15568

    Last Modified: 21 Nov 2024

    idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2019-15550

    Last Modified: 21 Nov 2024

    An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect crossing of a page boundary.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15569

    Last Modified: 21 Nov 2024

    HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2018-21000

    Last Modified: 21 Nov 2024

    An issue was discovered in the safe-transmute crate before 0.10.1 for Rust. A constructor's arguments are in the wrong order, causing heap memory corruption.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15570

    Last Modified: 21 Nov 2024

    BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.

    Published: 26 Aug 2019
    9.8
    Critical

    CVE-2019-15571

    Last Modified: 21 Nov 2024

    The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.

    Published: 26 Aug 2019
    7.5
    High

    CVE-2018-20999

    Last Modified: 21 Nov 2024

    An issue was discovered in the orion crate before 0.11.2 for Rust. reset() calls cause incorrect results.

    Published: 26 Aug 2019