CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-8018

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-8017

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-8014

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-8015

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-8016

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-8013

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8012

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8011

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8010

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-8009

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    8.8
    High

    CVE-2019-8008

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    7.8
    High

    CVE-2019-13520

    Last Modified: 21 Nov 2024

    Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted project files to overflow the buffer and execute code under the privileges of the application.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8007

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-8006

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8005

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8004

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-8003

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-8002

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure .

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-11924

    Last Modified: 21 Nov 2024

    A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-7965

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

    Published: 20 Aug 2019
    5.4
    Medium

    CVE-2019-4482

    Last Modified: 21 Nov 2024

    IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 164066.

    Published: 20 Aug 2019
    5.3
    Medium

    CVE-2019-4437

    Last Modified: 21 Nov 2024

    IBM API Connect 2018.1 through 2018.4.1.6 may inadvertently leak sensitive details about internal servers and network via API swagger. IBM X-force ID: 162947.

    Published: 20 Aug 2019
    8.2
    High

    CVE-2019-4424

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162770.

    Published: 20 Aug 2019
    8.2
    High

    CVE-2019-4340

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 161419.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-4338

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence 4.0 (SonarG) does not properly restrict the size or amount of resources that are requested or influenced by an actor. This weakness can be used to consume more resources than intended. IBM X-Force ID: 161417.

    Published: 20 Aug 2019
    6.5
    Medium

    CVE-2019-4167

    Last Modified: 21 Nov 2024

    IBM StoredIQ 7.6.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158700.

    Published: 20 Aug 2019
    5.4
    Medium

    CVE-2019-4120

    Last Modified: 21 Nov 2024

    IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158146.

    Published: 20 Aug 2019
    7.8
    High

    CVE-2019-4253

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root access privileges. IBM X-Force ID: 159941.

    Published: 20 Aug 2019
    7.8
    High

    CVE-2018-1796

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libraries and gain root privileges. IBM X-Force ID: 149426.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1636

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144441.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1635

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144439.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1634

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1633

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1632

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1631

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.

    Published: 20 Aug 2019
    6.7
    Medium

    CVE-2018-1630

    Last Modified: 21 Nov 2024

    IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.

    Published: 20 Aug 2019
    6.5
    Medium

    CVE-2019-3753

    Last Modified: 21 Nov 2024

    Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.

    Published: 20 Aug 2019
    4.3
    Medium

    CVE-2019-4485

    Last Modified: 21 Nov 2024

    IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164069.

    Published: 20 Aug 2019
    4.3
    Medium

    CVE-2019-4484

    Last Modified: 21 Nov 2024

    IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164068.

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-4483

    Last Modified: 21 Nov 2024

    IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164067.

    Published: 20 Aug 2019
    9.8
    Critical

    CVE-2019-4481

    Last Modified: 21 Nov 2024

    IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164064.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-4460

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.

    Published: 20 Aug 2019
    8.2
    High

    CVE-2019-4433

    Last Modified: 21 Nov 2024

    IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162890.

    Published: 20 Aug 2019
    5.7
    Medium

    CVE-2019-4425

    Last Modified: 21 Nov 2024

    IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, and 18.0.0.2 could allow a user to obtain highly sensitive information from another user by inserting links that would be clicked on by unsuspecting users. IBM X-Force ID: 162771.

    Published: 20 Aug 2019
    6.2
    Medium

    CVE-2019-4420

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive information that could aid in further attacks against the system. IBM X-Force ID: 162738.

    Published: 20 Aug 2019
    8.2
    High

    CVE-2019-4419

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162737.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-4402

    Last Modified: 21 Nov 2024

    IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause a denial of service via an unprotected API. IBM X-Force ID: 162263.

    Published: 20 Aug 2019
    7.5
    High

    CVE-2019-4310

    Last Modified: 21 Nov 2024

    IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036.

    Published: 20 Aug 2019
    4.3
    Medium

    CVE-2019-4308

    Last Modified: 21 Nov 2024

    IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034.

    Published: 20 Aug 2019
    7.8
    High

    CVE-2019-4294

    Last Modified: 21 Nov 2024

    IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.

    Published: 20 Aug 2019