CVE-2019-14380
Last Modified: 21 Nov 2024libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.
CVE-2019-14382
Last Modified: 21 Nov 2024DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
CVE-2019-14383
Last Modified: 21 Nov 2024J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
CVE-2018-20860
Last Modified: 21 Nov 2024libopenmpt before 0.3.13 allows a crash with malformed MED files.
CVE-2018-20861
Last Modified: 21 Nov 2024libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.
CVE-2018-20871
Last Modified: 21 Nov 2024In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).
CVE-2019-14242
Last Modified: 21 Nov 2024An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with administrator privileges can create a malicious DLL file in %SystemRoot%\System32\ that will be executed with local user privileges.
CVE-2019-14313
Last Modified: 21 Nov 2024A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.
CVE-2019-14318
Last Modified: 21 Nov 2024Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.
CVE-2019-11202
Last Modified: 21 Nov 2024An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials. This can be mitigated by deactivating the default admin user rather than completing deleting them.
CVE-2018-20870
Last Modified: 21 Nov 2024The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
CVE-2018-20869
Last Modified: 21 Nov 2024cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
CVE-2018-20862
Last Modified: 21 Nov 2024cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
CVE-2018-20868
Last Modified: 21 Nov 2024cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
CVE-2018-20866
Last Modified: 21 Nov 2024cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
CVE-2018-20865
Last Modified: 21 Nov 2024cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
CVE-2018-20864
Last Modified: 21 Nov 2024cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
CVE-2018-20863
Last Modified: 21 Nov 2024cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
CVE-2019-14414
Last Modified: 21 Nov 2024In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
CVE-2019-14413
Last Modified: 21 Nov 2024cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
CVE-2019-14412
Last Modified: 21 Nov 2024Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
CVE-2019-14411
Last Modified: 21 Nov 2024cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
CVE-2019-14410
Last Modified: 21 Nov 2024Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
CVE-2019-14409
Last Modified: 21 Nov 2024cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
CVE-2019-14408
Last Modified: 21 Nov 2024cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
CVE-2019-14407
Last Modified: 21 Nov 2024cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
CVE-2019-14406
Last Modified: 21 Nov 2024cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
CVE-2019-14405
Last Modified: 21 Nov 2024cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
CVE-2019-14404
Last Modified: 21 Nov 2024cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
CVE-2019-14403
Last Modified: 21 Nov 2024cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
CVE-2019-14402
Last Modified: 21 Nov 2024cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
CVE-2019-14401
Last Modified: 21 Nov 2024cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
CVE-2019-14400
Last Modified: 21 Nov 2024cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
CVE-2019-14399
Last Modified: 21 Nov 2024The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
CVE-2019-14398
Last Modified: 21 Nov 2024cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
CVE-2019-14397
Last Modified: 21 Nov 2024cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
CVE-2019-14396
Last Modified: 21 Nov 2024API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
CVE-2019-14395
Last Modified: 21 Nov 2024cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
CVE-2019-14394
Last Modified: 21 Nov 2024cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
CVE-2019-14393
Last Modified: 21 Nov 2024cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
CVE-2019-14392
Last Modified: 21 Nov 2024cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
CVE-2018-20867
Last Modified: 21 Nov 2024cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
CVE-2019-11775
Last Modified: 21 Nov 2024All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.
CVE-2019-4456
Last Modified: 21 Nov 2024IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 163620.
CVE-2019-4285
Last Modified: 21 Nov 2024IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim's click actions or launch other client-side browser attacks. IBM X-Force ID: 160513.
CVE-2019-4062
Last Modified: 21 Nov 2024IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 157007.
CVE-2019-14391
Last Modified: 21 Nov 2024cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
CVE-2019-14390
Last Modified: 21 Nov 2024cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
CVE-2019-14389
Last Modified: 21 Nov 2024cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
CVE-2019-14388
Last Modified: 21 Nov 2024cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
