CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2019-10365

    Last Modified: 21 Nov 2024

    Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.

    Published: 31 Jul 2019
    6.5
    Medium

    CVE-2019-10366

    Last Modified: 21 Nov 2024

    Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-10357

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.

    Published: 31 Jul 2019
    5.5
    Medium

    CVE-2019-10361

    Last Modified: 21 Nov 2024

    Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.

    Published: 31 Jul 2019
    5.4
    Medium

    CVE-2019-10362

    Last Modified: 21 Nov 2024

    Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of environment variables.

    Published: 31 Jul 2019
    3.3
    Low

    CVE-2019-10343

    Last Modified: 21 Nov 2024

    Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14193

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14199

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14196

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply.

    Published: 31 Jul 2019
    9.1
    Critical

    CVE-2019-14197

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14198

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv3 case.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14195

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the "else" block after calculating the new path length.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14194

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14192

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14200

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14201

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14202

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14203

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply.

    Published: 31 Jul 2019
    9.8
    Critical

    CVE-2019-14204

    Last Modified: 12 May 2026

    An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.

    Published: 31 Jul 2019
    6.5
    Medium

    CVE-2018-11782

    Last Modified: 21 Nov 2024

    In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.

    Published: 31 Jul 2019
    7.5
    High

    CVE-2019-0203

    Last Modified: 21 Nov 2024

    In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.

    Published: 31 Jul 2019
    —
    Unknown

    CVE-2019-14361

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-14439. Reason: This candidate is a reservation duplicate of CVE-2019-14439. Notes: All CVE users should reference CVE-2019-14439 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Jul 2019
    7.5
    High

    CVE-2019-14452

    Last Modified: 21 Nov 2024

    Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.

    Published: 31 Jul 2019
    7.2
    High

    CVE-2019-0193

    Last Modified: 27 Oct 2025

    In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.

    Published: 31 Jul 2019
    6.5
    Medium

    CVE-2019-14940

    Last Modified: 21 Nov 2024

    In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input.

    Published: 31 Jul 2019
    9.1
    Critical

    CVE-2019-17544

    Last Modified: 21 Nov 2024

    libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

    Published: 31 Jul 2019
    7.5
    High

    CVE-2019-16162

    Last Modified: 21 Nov 2024

    Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.

    Published: 31 Jul 2019
    4.7
    Medium

    CVE-2019-20919

    Last Modified: 21 Nov 2024

    An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.

    Published: 31 Jul 2019
    5.5
    Medium

    CVE-2020-14392

    Last Modified: 21 Nov 2024

    An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.

    Published: 31 Jul 2019
    4.3
    Medium

    CVE-2019-10163

    Last Modified: 21 Nov 2024

    A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

    Published: 30 Jul 2019
    7.5
    High

    CVE-2019-10162

    Last Modified: 21 Nov 2024

    A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.

    Published: 30 Jul 2019
    5.9
    Medium

    CVE-2019-7614

    Last Modified: 21 Nov 2024

    A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple users submitting requests, it could be possible for an attacker to gain access to response header containing sensitive data from another user.

    Published: 30 Jul 2019
    4.9
    Medium

    CVE-2019-7616

    Last Modified: 21 Nov 2024

    Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for Timelion visualizer. An attacker with administrative Kibana access could set the timelion:graphite.url configuration option to an arbitrary URL. This could possibly lead to an attacker accessing external URL resources as the Kibana process on the host system.

    Published: 30 Jul 2019
    7.4
    High

    CVE-2019-7615

    Last Modified: 21 Nov 2024

    A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via the 'server_ca_cert' setting, the Ruby agent would not properly verify the certificate returned by the APM server. This could result in a man in the middle style attack against the Ruby agent.

    Published: 30 Jul 2019
    5.5
    Medium

    CVE-2019-5460

    Last Modified: 21 Nov 2024

    Double Free in VLC versions <= 3.0.6 leads to a crash.

    Published: 30 Jul 2019
    4.3
    Medium

    CVE-2019-5449

    Last Modified: 21 Nov 2024

    A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.

    Published: 30 Jul 2019
    6.8
    Medium

    CVE-2019-5450

    Last Modified: 21 Nov 2024

    Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML.

    Published: 30 Jul 2019
    4.6
    Medium

    CVE-2019-5451

    Last Modified: 21 Nov 2024

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.

    Published: 30 Jul 2019
    2.4
    Low

    CVE-2019-5452

    Last Modified: 21 Nov 2024

    Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved.

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2019-5453

    Last Modified: 21 Nov 2024

    Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider.

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2019-5454

    Last Modified: 21 Nov 2024

    SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.

    Published: 30 Jul 2019
    6.8
    Medium

    CVE-2019-5455

    Last Modified: 21 Nov 2024

    Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.

    Published: 30 Jul 2019
    7.1
    High

    CVE-2019-5459

    Last Modified: 21 Nov 2024

    An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.

    Published: 30 Jul 2019
    5.4
    Medium

    CVE-2019-5457

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

    Published: 30 Jul 2019
    5.4
    Medium

    CVE-2019-5458

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.

    Published: 30 Jul 2019
    8.1
    High

    CVE-2019-5456

    Last Modified: 21 Nov 2024

    SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 and their actual SMTP server to record their SMTP credentials for malicious use later.

    Published: 30 Jul 2019
    8.1
    High

    CVE-2019-5448

    Last Modified: 21 Nov 2024

    Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2019-13026

    Last Modified: 21 Nov 2024

    OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2018-20859

    Last Modified: 21 Nov 2024

    edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.

    Published: 30 Jul 2019
    7.2
    High

    CVE-2017-18381

    Last Modified: 21 Nov 2024

    The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

    Published: 30 Jul 2019