CVE-2019-5033
Last Modified: 21 Nov 2024An exploitable out-of-bounds read vulnerability exists in the Number record parser of Aspose Aspose.Cells 19.1.0 library. A specially crafted XLS file can cause an out-of-bounds read, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
CVE-2019-3634
Last Modified: 21 Nov 2024Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via an encrypted message sent to DLPe which when decrypted results in DLPe reading unallocated memory.
CVE-2019-3633
Last Modified: 21 Nov 2024Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results in DLPe reading unallocated memory.
CVE-2017-18560
Last Modified: 21 Nov 2024The content-audit plugin before 1.9.2 for WordPress has XSS.
CVE-2017-18558
Last Modified: 21 Nov 2024The bws-testimonials plugin before 0.1.9 for WordPress has multiple XSS issues.
CVE-2017-18557
Last Modified: 21 Nov 2024The bws-google-maps plugin before 1.3.6 for WordPress has multiple XSS issues.
CVE-2017-18556
Last Modified: 21 Nov 2024The bws-google-analytics plugin before 1.7.1 for WordPress has multiple XSS issues.
CVE-2017-18555
Last Modified: 21 Nov 2024The booking-sms plugin before 1.1.0 for WordPress has XSS.
CVE-2017-18554
Last Modified: 21 Nov 2024The analytics-tracker plugin before 1.1.1 for WordPress has XSS via a search event.
CVE-2017-18553
Last Modified: 21 Nov 2024The ad-buttons plugin before 2.3.2 for WordPress has XSS.
CVE-2016-10903
Last Modified: 21 Nov 2024The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
CVE-2016-10902
Last Modified: 21 Nov 2024The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
CVE-2016-10909
Last Modified: 21 Nov 2024The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CVE-2016-10901
Last Modified: 21 Nov 2024The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
CVE-2016-10908
Last Modified: 21 Nov 2024The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
CVE-2016-10900
Last Modified: 21 Nov 2024The uji-countdown plugin before 2.0.7 for WordPress has XSS.
CVE-2019-15112
Last Modified: 21 Nov 2024The wp-slimstat plugin before 4.8.1 for WordPress has XSS.
CVE-2017-18565
Last Modified: 21 Nov 2024The updater plugin before 1.35 for WordPress has multiple XSS issues.
CVE-2019-15111
Last Modified: 21 Nov 2024The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue.
CVE-2019-15110
Last Modified: 21 Nov 2024The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS.
CVE-2017-18540
Last Modified: 21 Nov 2024The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
CVE-2017-18539
Last Modified: 21 Nov 2024The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
CVE-2017-18538
Last Modified: 21 Nov 2024The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
CVE-2017-18537
Last Modified: 21 Nov 2024The visitors-online plugin before 1.0.0 for WordPress has multiple XSS issues.
CVE-2016-10898
Last Modified: 21 Nov 2024The total-security plugin before 3.4.1 for WordPress has XSS.
CVE-2016-10899
Last Modified: 21 Nov 2024The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
CVE-2019-15109
Last Modified: 21 Nov 2024The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
CVE-2015-9321
Last Modified: 21 Nov 2024The shortcode-factory plugin before 1.1.1 for WordPress has XSS via add_query_arg.
CVE-2017-18534
Last Modified: 21 Nov 2024The share-on-diaspora plugin before 0.7.2 for WordPress has reflected XSS in share URL parameters.
CVE-2016-10897
Last Modified: 21 Nov 2024The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
CVE-2017-18536
Last Modified: 23 Jan 2026The stop-user-enumeration plugin before 1.3.8 for WordPress has XSS.
CVE-2016-10896
Last Modified: 21 Nov 2024The seo-redirection plugin before 4.3 for WordPress has stored XSS.
CVE-2019-15296
Last Modified: 21 Nov 2024An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The faad_resetbits function in libfaad/bits.c is affected by a buffer overflow vulnerability. The number of bits to be read is determined by ld->buffer_size - words*4, cast to uint32. If ld->buffer_size - words*4 is negative, a buffer overflow is later performed via getdword_n(&ld->start[words], ld->bytes_left).
CVE-2019-15293
Last Modified: 21 Nov 2024An issue was discovered in ACDSee Photo Studio Standard 22.1 Build 1159. There is a User Mode Write AV starting at IDE_ACDStd!IEP_ShowPlugInDialog+0x000000000023d060.
CVE-2019-19533
Last Modified: 21 Nov 2024In the Linux kernel before 5.3.4, there is an info-leak bug that can be caused by a malicious USB device in the drivers/media/usb/ttusb-dec/ttusb_dec.c driver, aka CID-a10feaf8c464.
CVE-2019-12746
Last Modified: 21 Nov 2024An issue was discovered in Open Ticket Request System (OTRS) Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then be potentially abused in order to impersonate the agent user.
CVE-2019-15292
Last Modified: 21 Nov 2024An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.
CVE-2019-13458
Last Modified: 21 Nov 2024An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, and Community Edition 5.0.x through 5.0.36 and 6.0.x through 6.0.19. An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS notification tags in templates in order to disclose hashed user passwords.
CVE-2019-5036
Last Modified: 21 Nov 2024An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially crafted packet to trigger this vulnerability.
CVE-2019-5035
Last Modified: 21 Nov 2024An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker can send specially crafted packets to trigger this vulnerability.
CVE-2019-5034
Last Modified: 21 Nov 2024An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vulnerability.
CVE-2019-10960
Last Modified: 21 Nov 2024Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.
CVE-2019-5040
Last Modified: 21 Nov 2024An exploitable information disclosure vulnerability exists in the Weave MessageLayer parsing of Openweave-core version 4.0.2 and Nest Cam IQ Indoor version 4620002. A specially crafted weave packet can cause an integer overflow to occur, resulting in PacketBuffer data reuse. An attacker can send a packet to trigger this vulnerability.
CVE-2019-5037
Last Modified: 21 Nov 2024An exploitable denial-of-service vulnerability exists in the Weave certificate loading functionality of Nest Cam IQ Indoor camera, version 4620002. A specially crafted weave packet can cause an integer overflow and an out-of-bounds read on unmapped memory to occur, resulting in a denial of service. An attacker can send a specially crafted packet to trigger.
CVE-2019-5039
Last Modified: 21 Nov 2024An exploitable command execution vulnerability exists in the ASN1 certificate writing functionality of Openweave-core version 4.0.2. A specially crafted weave certificate can trigger a heap-based buffer overflow, resulting in code execution. An attacker can craft a weave certificate to trigger this vulnerability.
CVE-2019-5038
Last Modified: 21 Nov 2024An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a specially crafted Weave command.
CVE-2019-8106
Last Modified: 21 Nov 2024Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
CVE-2019-8105
Last Modified: 21 Nov 2024Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
CVE-2019-8104
Last Modified: 21 Nov 2024Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
CVE-2019-8103
Last Modified: 21 Nov 2024Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .
