CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-1929

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 7 Aug 2019
    8.8
    High

    CVE-2019-1934

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker to elevate privileges and execute administrative functions on an affected device. The vulnerability is due to insufficient authorization validation. An attacker could exploit this vulnerability by logging in to an affected device as a low-privileged user and then sending specific HTTPS requests to execute administrative functions using the information retrieved during initial login.

    Published: 7 Aug 2019
    7.3
    High

    CVE-2019-1944

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is being established. For more information about these vulnerabilities, see the Details section of this security advisory.

    Published: 7 Aug 2019
    7.8
    High

    CVE-2019-1926

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 7 Aug 2019
    7.8
    High

    CVE-2019-1927

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 7 Aug 2019
    7.4
    High

    CVE-2019-1918

    Last Modified: 21 Nov 2024

    A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending specific link-state PDUs to an affected system to be processed. A successful exploit could allow the attacker to cause incorrect calculations used in the weighted remote shared risk link groups (SRLG) or in the IGP Flexible Algorithm. It could also cause tracebacks to the logs or potentially cause the receiving device to crash the IS–IS process, resulting in a DoS condition.

    Published: 7 Aug 2019
    7.8
    High

    CVE-2019-1924

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 7 Aug 2019
    7.8
    High

    CVE-2019-1925

    Last Modified: 21 Nov 2024

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit these vulnerabilities by sending a user a malicious ARF or WRF file through a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system with the privileges of the targeted user.

    Published: 7 Aug 2019
    7.4
    High

    CVE-2019-1910

    Last Modified: 21 Nov 2024

    A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol data units (PDUs). An attacker could exploit this vulnerability by sending a crafted link-state PDU to an affected system to be processed. A successful exploit could allow the attacker to cause all routers within the IS–IS area to unexpectedly restart the IS–IS process, resulting in a DoS condition. This vulnerability affects Cisco devices if they are running a vulnerable release of Cisco IOS XR Software earlier than Release 6.6.3 and are configured with the IS–IS routing protocol. Cisco has confirmed that this vulnerability affects both Cisco IOS XR 32-bit Software and Cisco IOS XR 64-bit Software.

    Published: 7 Aug 2019
    9.8
    Critical

    CVE-2019-1895

    Last Modified: 24 Aug 2026

    A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.

    Published: 7 Aug 2019
    7.5
    High

    CVE-2019-14474

    Last Modified: 21 Nov 2024

    eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, resulting in the ability to start a Denial of Service. Due to Improper Authorization an attacker can obtain a session ID from CVE-2019-9583 or a valid guest/user/admin account can start this attack too.

    Published: 7 Aug 2019
    9.8
    Critical

    CVE-2019-14537

    Last Modified: 21 Nov 2024

    YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

    Published: 7 Aug 2019
    5.4
    Medium

    CVE-2019-14748

    Last Modified: 21 Nov 2024

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.

    Published: 7 Aug 2019
    8.8
    High

    CVE-2019-14749

    Last Modified: 21 Nov 2024

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.

    Published: 7 Aug 2019
    6.1
    Medium

    CVE-2019-14750

    Last Modified: 21 Nov 2024

    An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

    Published: 7 Aug 2019
    5.4
    Medium

    CVE-2019-11653

    Last Modified: 21 Nov 2024

    Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploited to manipulate data stored during another user’s CheckIn request.

    Published: 7 Aug 2019
    9.8
    Critical

    CVE-2019-5476

    Last Modified: 21 Nov 2024

    An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.

    Published: 7 Aug 2019
    7.5
    High

    CVE-2019-10099

    Last Modified: 21 Nov 2024

    Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encryption.enabled=true. This includes cached blocks that are fetched to disk (controlled by spark.maxRemoteBlockSizeFetchToMem); in SparkR, using parallelize; in Pyspark, using broadcast and parallelize; and use of python udfs.

    Published: 7 Aug 2019
    7.5
    High

    CVE-2016-5431

    Last Modified: 21 Nov 2024

    The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component resulting in bypassing the signature verification via crafted tokens.

    Published: 7 Aug 2019
    6.1
    Medium

    CVE-2019-14747

    Last Modified: 21 Nov 2024

    DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.

    Published: 7 Aug 2019
    9.8
    Critical

    CVE-2019-14746

    Last Modified: 21 Nov 2024

    A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.

    Published: 7 Aug 2019
    7.8
    High

    CVE-2019-14745

    Last Modified: 21 Nov 2024

    In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.

    Published: 7 Aug 2019
    8.8
    High

    CVE-2019-14432

    Last Modified: 21 Nov 2024

    Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is recording a video with the application. The same attack vector can be used to crash the application at any time.

    Published: 7 Aug 2019
    7.8
    High

    CVE-2019-14744

    Last Modified: 21 Nov 2024

    In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10387

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 7 Aug 2019
    4.3
    Medium

    CVE-2019-10388

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.

    Published: 7 Aug 2019
    4.3
    Medium

    CVE-2019-10389

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to have Jenkins initiate an HTTP connection to an attacker-specified server.

    Published: 7 Aug 2019
    5.4
    Medium

    CVE-2019-10373

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline description to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

    Published: 7 Aug 2019
    7.5
    High

    CVE-2019-10371

    Last Modified: 21 Nov 2024

    A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

    Published: 7 Aug 2019
    6.1
    Medium

    CVE-2019-10372

    Last Modified: 21 Nov 2024

    An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.

    Published: 7 Aug 2019
    5.4
    Medium

    CVE-2019-10374

    Last Modified: 21 Nov 2024

    A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other fields rendered using the configured markup formatter to insert links with the javascript scheme into the Jenkins UI.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10375

    Last Modified: 21 Nov 2024

    An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master.

    Published: 7 Aug 2019
    6.1
    Medium

    CVE-2019-10376

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

    Published: 7 Aug 2019
    4.3
    Medium

    CVE-2019-10377

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.

    Published: 7 Aug 2019
    5.3
    Medium

    CVE-2019-10378

    Last Modified: 21 Nov 2024

    Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10379

    Last Modified: 21 Nov 2024

    Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 7 Aug 2019
    7.5
    High

    CVE-2019-10381

    Last Modified: 21 Nov 2024

    Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10382

    Last Modified: 21 Nov 2024

    Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

    Published: 7 Aug 2019
    8.8
    High

    CVE-2019-10386

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 7 Aug 2019
    8.8
    High

    CVE-2019-10380

    Last Modified: 21 Nov 2024

    Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10385

    Last Modified: 21 Nov 2024

    Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10370

    Last Modified: 21 Nov 2024

    Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially resulting in their exposure.

    Published: 7 Aug 2019
    5.5
    Medium

    CVE-2019-10367

    Last Modified: 21 Nov 2024

    Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2019-10369

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 7 Aug 2019
    8.8
    High

    CVE-2019-10368

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 7 Aug 2019
    7.5
    High

    CVE-2018-14383

    Last Modified: 21 Nov 2024

    The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7

    Published: 7 Aug 2019
    6.6
    Medium

    CVE-2019-14743

    Last Modified: 21 Nov 2024

    In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.

    Published: 7 Aug 2019
    8.1
    High

    CVE-2018-20959

    Last Modified: 21 Nov 2024

    Jura E8 devices lack Bluetooth connection security.

    Published: 7 Aug 2019
    6.5
    Medium

    CVE-2018-20958

    Last Modified: 21 Nov 2024

    The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.

    Published: 7 Aug 2019
    6.1
    Medium

    CVE-2017-18483

    Last Modified: 21 Nov 2024

    ANNKE SP1 HD wireless camera 3.4.1.1604071109 devices allow XSS via a crafted SSID.

    Published: 7 Aug 2019