CVE-2019-19536
Last Modified: 21 Nov 2024In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_pro.c driver, aka CID-ead16e53c2f0.
CVE-2019-14517
Last Modified: 21 Nov 2024pandao Editor.md 1.5.0 allows XSS via the Javascript: string.
CVE-2019-5401
Last Modified: 21 Nov 2024A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss injection by setting the attack vector in one of the switch persistent configuration fields (management URL, location, contact). But admin privileges are required to configure these fields thereby reducing the likelihood of exploit. HPE Aruba has provided firmware updates to resolve the vulnerability in HP 2910-48G al Switch. Please update to W.15.14.0017.
CVE-2019-14513
Last Modified: 21 Nov 2024Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.
CVE-2019-14260
Last Modified: 21 Nov 2024On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.
CVE-2016-10813
Last Modified: 21 Nov 2024cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).
CVE-2016-10814
Last Modified: 21 Nov 2024cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).
CVE-2016-10815
Last Modified: 21 Nov 2024cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
CVE-2016-10816
Last Modified: 21 Nov 2024cPanel before 57.9999.54 allows Webmail accounts to execute arbitrary code through forwarders (SEC-121).
CVE-2016-10817
Last Modified: 21 Nov 2024cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
CVE-2016-10818
Last Modified: 21 Nov 2024cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
CVE-2016-10819
Last Modified: 21 Nov 2024In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
CVE-2016-10820
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
CVE-2016-10821
Last Modified: 21 Nov 2024In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
CVE-2016-10826
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
CVE-2019-14497
Last Modified: 21 Nov 2024ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.
CVE-2019-14496
Last Modified: 21 Nov 2024LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.
CVE-2019-9140
Last Modified: 21 Nov 2024When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.
CVE-2019-14495
Last Modified: 21 Nov 2024webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.
CVE-2016-10822
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).
CVE-2016-10823
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).
CVE-2016-10824
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).
CVE-2016-10825
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
CVE-2016-10827
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows self stored XSS in WHM Edit System Mail Preferences (SEC-96).
CVE-2016-10828
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
CVE-2016-10829
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
CVE-2016-10830
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
CVE-2016-10831
Last Modified: 21 Nov 2024cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
CVE-2018-20953
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
CVE-2018-20952
Last Modified: 21 Nov 2024cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
CVE-2018-20951
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
CVE-2018-20950
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
CVE-2018-20949
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
CVE-2018-20948
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
CVE-2018-20947
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
CVE-2018-20946
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
CVE-2018-20945
Last Modified: 21 Nov 2024bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
CVE-2018-20944
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
CVE-2016-10832
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
CVE-2018-20943
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
CVE-2018-20942
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
CVE-2018-20941
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
CVE-2016-10833
Last Modified: 21 Nov 2024cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
CVE-2018-20940
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
CVE-2018-20939
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
CVE-2018-20938
Last Modified: 21 Nov 2024cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).
CVE-2016-10834
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
CVE-2018-20937
Last Modified: 21 Nov 2024cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
CVE-2016-10835
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).
CVE-2018-20936
Last Modified: 21 Nov 2024cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
