CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-14336

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated dump of all of the config files through a certain admin.cgi?action= insecure HTTP request.

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2019-14334

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP command.

    Published: 1 Aug 2019
    5.5
    Medium

    CVE-2019-14333

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a pre-authenticated denial of service attack against the access point via a long action parameter to admin.cgi.

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-14332

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is use of weak ciphers for SSH such as diffie-hellman-group1-sha1.

    Published: 1 Aug 2019
    9.8
    Critical

    CVE-2019-14234

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.

    Published: 1 Aug 2019
    7.5
    High

    CVE-2019-14232

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.

    Published: 1 Aug 2019
    7.5
    High

    CVE-2019-14233

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete HTML entities.

    Published: 1 Aug 2019
    7.5
    High

    CVE-2019-14235

    Last Modified: 21 Nov 2024

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid UTF-8 octet sequences.

    Published: 1 Aug 2019
    8.2
    High

    CVE-2019-14491

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvaluator> in modules/objdetect/src/cascadedetect.hpp, which leads to denial of service.

    Published: 1 Aug 2019
    7.1
    High

    CVE-2020-14393

    Last Modified: 21 Nov 2024

    A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-4473

    Last Modified: 21 Nov 2024

    Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.

    Published: 1 Aug 2019
    7.8
    High

    CVE-2019-14465

    Last Modified: 21 Nov 2024

    fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow.

    Published: 31 Jul 2019
    5.5
    Medium

    CVE-2019-14464

    Last Modified: 21 Nov 2024

    XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.

    Published: 31 Jul 2019
    9.1
    Critical

    CVE-2019-14463

    Last Modified: 21 Nov 2024

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.

    Published: 31 Jul 2019
    9.1
    Critical

    CVE-2019-14462

    Last Modified: 21 Nov 2024

    An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.

    Published: 31 Jul 2019
    6.1
    Medium

    CVE-2019-7000

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-10186

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML loading/unloading admin tool.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-10187

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary were able to delete entries from other glossaries they did not have direct access to.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-10188

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-10189

    Last Modified: 21 Nov 2024

    A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overrides for other groups in the same assignment.

    Published: 31 Jul 2019
    7.5
    High

    CVE-2019-14459

    Last Modified: 21 Nov 2024

    nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).

    Published: 31 Jul 2019
    5.4
    Medium

    CVE-2019-14456

    Last Modified: 21 Nov 2024

    Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server) sends crafted text to a serial port (that has logging enabled), the text will be replayed when the logs are viewed. Exploiting this vulnerability requires access to the serial port and/or console server.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-12797

    Last Modified: 21 Nov 2024

    A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus of a vehicle.

    Published: 31 Jul 2019
    7.8
    High

    CVE-2019-12750

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.1.7491.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published: 31 Jul 2019
    5.4
    Medium

    CVE-2019-3958

    Last Modified: 21 Nov 2024

    Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks via a crafted sales transaction.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-1901

    Last Modified: 21 Nov 2024

    A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an adjacent, unauthenticated attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges. The vulnerability is due to improper input validation of certain type, length, value (TLV) fields of the LLDP frame header. An attacker could exploit this vulnerability by sending a crafted LLDP packet to the targeted device. A successful exploit may lead to a buffer overflow condition that could either cause a DoS condition or allow the attacker to execute arbitrary code with root privileges. Note: This vulnerability cannot be exploited by transit traffic through the device; the crafted packet must be targeted to a directly connected interface. This vulnerability affects Cisco Nexus 9000 Series Fabric Switches in ACI mode if they are running a Cisco Nexus 9000 Series ACI Mode Switch Software release prior to 13.2(7f) or any 14.x release.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-3959

    Last Modified: 21 Nov 2024

    Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

    Published: 31 Jul 2019
    7.2
    High

    CVE-2019-3960

    Last Modified: 21 Nov 2024

    Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

    Published: 31 Jul 2019
    6.5
    Medium

    CVE-2018-20872

    Last Modified: 21 Nov 2024

    DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2007-6763

    Last Modified: 21 Nov 2024

    SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-5060

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-5059

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-5058

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-5057

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

    Published: 31 Jul 2019
    5.5
    Medium

    CVE-2019-5020

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.

    Published: 31 Jul 2019
    7.5
    High

    CVE-2019-4165

    Last Modified: 21 Nov 2024

    IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow a remote attacker to cause a denial of service attack using repeated requests to the server. IBM X-Force ID: 158698.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-4163

    Last Modified: 21 Nov 2024

    IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privileged user should only be allowed to view. IBM X-Force ID: 158696.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-13568

    Last Modified: 21 Nov 2024

    CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a malformed BMP image.

    Published: 31 Jul 2019
    8.1
    High

    CVE-2019-10181

    Last Modified: 21 Nov 2024

    It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

    Published: 31 Jul 2019
    8.6
    High

    CVE-2019-10185

    Last Modified: 21 Nov 2024

    It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

    Published: 31 Jul 2019
    8.2
    High

    CVE-2019-10182

    Last Modified: 21 Nov 2024

    It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-10356

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.

    Published: 31 Jul 2019
    6.5
    Medium

    CVE-2019-10358

    Last Modified: 21 Nov 2024

    Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables in the build log.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-10344

    Last Modified: 21 Nov 2024

    Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.

    Published: 31 Jul 2019
    5.5
    Medium

    CVE-2019-10345

    Last Modified: 21 Nov 2024

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

    Published: 31 Jul 2019
    8.8
    High

    CVE-2019-10355

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.

    Published: 31 Jul 2019
    6.3
    Medium

    CVE-2019-10359

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.

    Published: 31 Jul 2019
    5.4
    Medium

    CVE-2019-10360

    Last Modified: 21 Nov 2024

    A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

    Published: 31 Jul 2019
    4.9
    Medium

    CVE-2019-10363

    Last Modified: 21 Nov 2024

    Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.

    Published: 31 Jul 2019
    5.5
    Medium

    CVE-2019-10364

    Last Modified: 21 Nov 2024

    Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.

    Published: 31 Jul 2019