CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-1004

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1056, CVE-2019-1059.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-1001

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1004, CVE-2019-1056, CVE-2019-1059.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-1006

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.

    Published: 15 Jul 2019
    7
    High

    CVE-2019-1037

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-1056

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1059.

    Published: 15 Jul 2019
    5.5
    Medium

    CVE-2019-1073

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1071.

    Published: 15 Jul 2019
    7.8
    High

    CVE-2019-1067

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'.

    Published: 15 Jul 2019
    7.8
    High

    CVE-2019-1082

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Microsoft Windows where a certain DLL, with Local Service privilege, is vulnerable to race planting a customized DLL.An attacker who successfully exploited this vulnerability could potentially elevate privilege to SYSTEM.The update addresses this vulnerability by requiring SYSTEM privileges for a certain DLL., aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1074.

    Published: 15 Jul 2019
    8
    High

    CVE-2019-0887

    Last Modified: 7 Jul 2025

    A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-0865

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'.

    Published: 15 Jul 2019
    6.3
    Medium

    CVE-2019-0975

    Last Modified: 21 Nov 2024

    A security feature bypass vulnerability exists when Active Directory Federation Services (ADFS) improperly updates its list of banned IP addresses. To exploit this vulnerability, an attacker would have to convince a victim ADFS administrator to update the list of banned IP addresses. This security update corrects how ADFS updates its list of banned IP addresses., aka 'ADFS Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-1126.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-0811

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Windows DNS Server when it fails to properly handle DNS queries, aka 'Windows DNS Server Denial of Service Vulnerability'.

    Published: 15 Jul 2019
    4.9
    Medium

    CVE-2019-0962

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'.

    Published: 15 Jul 2019
    6.8
    Medium

    CVE-2019-0966

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Windows Hyper-V Denial of Service Vulnerability'.

    Published: 15 Jul 2019
    7.8
    High

    CVE-2019-0999

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.

    Published: 15 Jul 2019
    7.8
    High

    CVE-2019-0880

    Last Modified: 29 Oct 2025

    A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-0785

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

    Published: 15 Jul 2019
    5.3
    Medium

    CVE-2019-5447

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010293

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-1010294

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010295

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010296

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010297

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010298

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-1010300

    Last Modified: 21 Nov 2024

    mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet.

    Published: 15 Jul 2019
    5.5
    Medium

    CVE-2019-1010301

    Last Modified: 21 Nov 2024

    jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.

    Published: 15 Jul 2019
    5.5
    Medium

    CVE-2019-1010302

    Last Modified: 21 Nov 2024

    jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.

    Published: 15 Jul 2019
    5.4
    Medium

    CVE-2019-1010307

    Last Modified: 21 Nov 2024

    GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the "Link Tickets" feature, 3- a request to the endpoint fetches js and executes it.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010308

    Last Modified: 21 Nov 2024

    Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.

    Published: 15 Jul 2019
    —
    Unknown

    CVE-2019-1010042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7662. Reason: This candidate is a reservation duplicate of CVE-2018-7662. Notes: All CVE users should reference CVE-2018-7662 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010044

    Last Modified: 21 Nov 2024

    borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable.

    Published: 15 Jul 2019
    5.3
    Medium

    CVE-2019-1010304

    Last Modified: 21 Nov 2024

    Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. The impact is: Important. The component is: ProductVariant type in GraphQL API. The attack vector is: Unauthenticated user can access the GraphQL API (which is by default publicly exposed under `/graphql/` URL) and fetch products data which may include admin-restricted shop's revenue data. The fixed version is: 2.3.1.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010306

    Last Modified: 21 Nov 2024

    Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.

    Published: 15 Jul 2019
    5.9
    Medium

    CVE-2019-13604

    Last Modified: 21 Nov 2024

    There is a short key vulnerability in HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader v24. The key for obfuscating the fingerprint image is vulnerable to brute-force attacks. This allows an attacker to recover the key and decrypt that image using the key. Successful exploitation causes a sensitive biometric information leak.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010039

    Last Modified: 21 Nov 2024

    uLaunchELF < commit 170827a is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Loader program (loader.c) overly trusts the arguments provided via command line.

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010038

    Last Modified: 21 Nov 2024

    OpenModelica OMCompiler is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: OPENMODELICAHOME parameter changeable via environment variable. The attack vector is: Changing an environment variable.

    Published: 15 Jul 2019
    6.5
    Medium

    CVE-2014-10374

    Last Modified: 21 Nov 2024

    On Fitbit activity-tracker devices, certain addresses never change. According to the popets-2019-0036.pdf document, this leads to "permanent trackability" and "considerable privacy concerns" without a user-accessible anonymization feature. The devices, such as Charge 2, transmit Bluetooth Low Energy (BLE) advertising packets with a TxAdd flag indicating random addresses, but the addresses remain constant. If devices come within BLE range at one or more locations where an adversary has set up passive sniffing, the adversary can determine whether the same device has entered one of these locations.

    Published: 15 Jul 2019
    6.5
    Medium

    CVE-2019-1010034

    Last Modified: 21 Nov 2024

    Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in with at least Volunteer role or manage_circulation capabilities. PoC : /wordpress/wp-admin/admin.php?page=weblib-circulation-desk&orderby=title&order=DESC.

    Published: 15 Jul 2019
    —
    Unknown

    CVE-2019-1010030

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11501. Reason: This candidate is a reservation duplicate of CVE-2018-11501. Notes: All CVE users should reference CVE-2018-11501 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Jul 2019
    6.1
    Medium

    CVE-2019-1010028

    Last Modified: 21 Nov 2024

    phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />.

    Published: 15 Jul 2019
    7.5
    High

    CVE-2019-1010017

    Last Modified: 21 Nov 2024

    libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.

    Published: 15 Jul 2019
    6.1
    Medium

    CVE-2019-1010016

    Last Modified: 21 Nov 2024

    Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.

    Published: 15 Jul 2019
    —
    Unknown

    CVE-2019-1010011

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10753, CVE-2018-10771. Reason: This candidate is a reservation duplicate of CVE-2018-10753 and CVE-2018-10771. Notes: All CVE users should reference CVE-2018-10753 and CVE-2018-10771 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Jul 2019
    9.8
    Critical

    CVE-2019-1010009

    Last Modified: 21 Nov 2024

    DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT API. The attack vector is: Any Accessible Server.

    Published: 15 Jul 2019
    5.4
    Medium

    CVE-2019-1010008

    Last Modified: 21 Nov 2024

    OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in "Name", "Location", "Bio" and "Starting Page" fields in the "My Account" page. File: Lib/listjs/list.js, line 67. The attack vector is: unknown, victim must open profile page if persistent was possible.

    Published: 15 Jul 2019
    6.1
    Medium

    CVE-2019-1010005

    Last Modified: 21 Nov 2024

    HexoEditor v1.1.8-beta is affected by: XSS to code execution.

    Published: 15 Jul 2019
    5.4
    Medium

    CVE-2019-1010023

    Last Modified: 21 Nov 2024

    GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

    Published: 15 Jul 2019
    5.3
    Medium

    CVE-2019-1010024

    Last Modified: 21 Nov 2024

    GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

    Published: 15 Jul 2019
    5.5
    Medium

    CVE-2019-1010305

    Last Modified: 21 Nov 2024

    libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.

    Published: 15 Jul 2019
    6.5
    Medium

    CVE-2019-5847

    Last Modified: 21 Nov 2024

    Inappropriate implementation in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 15 Jul 2019