CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-14380

    Last Modified: 21 Nov 2024

    libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-14382

    Last Modified: 21 Nov 2024

    DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2019-14383

    Last Modified: 21 Nov 2024

    J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2018-20860

    Last Modified: 21 Nov 2024

    libopenmpt before 0.3.13 allows a crash with malformed MED files.

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2018-20861

    Last Modified: 21 Nov 2024

    libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files.

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2018-20871

    Last Modified: 21 Nov 2024

    In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).

    Published: 30 Jul 2019
    6.7
    Medium

    CVE-2019-14242

    Last Modified: 21 Nov 2024

    An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with administrator privileges can create a malicious DLL file in %SystemRoot%\System32\ that will be executed with local user privileges.

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2019-14313

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via filemanager/model.php.

    Published: 30 Jul 2019
    5.9
    Medium

    CVE-2019-14318

    Last Modified: 21 Nov 2024

    Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2019-11202

    Last Modified: 21 Nov 2024

    An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a default admin user with a well-known password. After initial setup, the Rancher administrator may choose to delete this default admin user. If Rancher is restarted, the default admin user will be recreated with the well-known default password. An attacker could exploit this by logging in with the default admin credentials. This can be mitigated by deactivating the default admin user rather than completing deleting them.

    Published: 30 Jul 2019
    5.5
    Medium

    CVE-2018-20870

    Last Modified: 21 Nov 2024

    The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

    Published: 30 Jul 2019
    7.8
    High

    CVE-2018-20869

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).

    Published: 30 Jul 2019
    7.8
    High

    CVE-2018-20862

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2018-20868

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2018-20866

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2018-20865

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).

    Published: 30 Jul 2019
    6.5
    Medium

    CVE-2018-20864

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

    Published: 30 Jul 2019
    9.8
    Critical

    CVE-2018-20863

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14414

    Last Modified: 21 Nov 2024

    In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).

    Published: 30 Jul 2019
    4.3
    Medium

    CVE-2019-14413

    Last Modified: 21 Nov 2024

    cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14412

    Last Modified: 21 Nov 2024

    Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).

    Published: 30 Jul 2019
    5.3
    Medium

    CVE-2019-14411

    Last Modified: 21 Nov 2024

    cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14410

    Last Modified: 21 Nov 2024

    Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).

    Published: 30 Jul 2019
    5.5
    Medium

    CVE-2019-14409

    Last Modified: 21 Nov 2024

    cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).

    Published: 30 Jul 2019
    4.3
    Medium

    CVE-2019-14408

    Last Modified: 21 Nov 2024

    cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).

    Published: 30 Jul 2019
    2.7
    Low

    CVE-2019-14407

    Last Modified: 21 Nov 2024

    cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2019-14406

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-14405

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

    Published: 30 Jul 2019
    5.5
    Medium

    CVE-2019-14404

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).

    Published: 30 Jul 2019
    4.3
    Medium

    CVE-2019-14403

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14402

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-14401

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).

    Published: 30 Jul 2019
    7.8
    High

    CVE-2019-14400

    Last Modified: 21 Nov 2024

    cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).

    Published: 30 Jul 2019
    7.1
    High

    CVE-2019-14399

    Last Modified: 21 Nov 2024

    The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-14398

    Last Modified: 21 Nov 2024

    cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).

    Published: 30 Jul 2019
    5.3
    Medium

    CVE-2019-14397

    Last Modified: 21 Nov 2024

    cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14396

    Last Modified: 21 Nov 2024

    API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14395

    Last Modified: 21 Nov 2024

    cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).

    Published: 30 Jul 2019
    5.5
    Medium

    CVE-2019-14394

    Last Modified: 21 Nov 2024

    cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).

    Published: 30 Jul 2019
    5.3
    Medium

    CVE-2019-14393

    Last Modified: 21 Nov 2024

    cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).

    Published: 30 Jul 2019
    8.8
    High

    CVE-2019-14392

    Last Modified: 21 Nov 2024

    cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).

    Published: 30 Jul 2019
    6.1
    Medium

    CVE-2018-20867

    Last Modified: 21 Nov 2024

    cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

    Published: 30 Jul 2019
    7.4
    High

    CVE-2019-11775

    Last Modified: 21 Nov 2024

    All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.

    Published: 30 Jul 2019
    7.1
    High

    CVE-2019-4456

    Last Modified: 21 Nov 2024

    IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 163620.

    Published: 30 Jul 2019
    5.4
    Medium

    CVE-2019-4285

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim's click actions or launch other client-side browser attacks. IBM X-Force ID: 160513.

    Published: 30 Jul 2019
    7.1
    High

    CVE-2019-4062

    Last Modified: 21 Nov 2024

    IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 157007.

    Published: 30 Jul 2019
    3.3
    Low

    CVE-2019-14391

    Last Modified: 21 Nov 2024

    cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).

    Published: 30 Jul 2019
    5.4
    Medium

    CVE-2019-14390

    Last Modified: 21 Nov 2024

    cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).

    Published: 30 Jul 2019
    7.8
    High

    CVE-2019-14389

    Last Modified: 21 Nov 2024

    cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).

    Published: 30 Jul 2019
    7.5
    High

    CVE-2019-14388

    Last Modified: 21 Nov 2024

    cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).

    Published: 30 Jul 2019