CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-11710

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    8.3
    High

    CVE-2019-11716

    Last Modified: 21 Nov 2024

    Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    5.3
    Medium

    CVE-2019-11727

    Last Modified: 21 Nov 2024

    A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    5.3
    Medium

    CVE-2019-11718

    Last Modified: 21 Nov 2024

    Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-11724

    Last Modified: 21 Nov 2024

    Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now redirects to another site. This additional permission is unnecessary and is a potential vector for malicious attacks. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    6.5
    Medium

    CVE-2019-11725

    Last Modified: 21 Nov 2024

    When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    6.5
    Medium

    CVE-2019-13454

    Last Modified: 11 Jul 2025

    ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.

    Published: 9 Jul 2019
    4.2
    Medium

    CVE-2019-10176

    Last Modified: 21 Nov 2024

    A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.

    Published: 9 Jul 2019
    9.8
    Critical

    CVE-2019-11714

    Last Modified: 21 Nov 2024

    Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    6.1
    Medium

    CVE-2019-11720

    Last Modified: 21 Nov 2024

    Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    6.5
    Medium

    CVE-2019-11721

    Last Modified: 21 Nov 2024

    The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    7.5
    High

    CVE-2019-11723

    Last Modified: 21 Nov 2024

    A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. This could leak cookies in private browsing mode or across different "containers" for people who use the Firefox Multi-Account Containers Web Extension. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    4.7
    Medium

    CVE-2019-11728

    Last Modified: 21 Nov 2024

    The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.

    Published: 9 Jul 2019
    —
    Unknown

    CVE-2019-13369

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Jul 2019
    6.1
    Medium

    CVE-2019-12927

    Last Modified: 21 Nov 2024

    MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.

    Published: 8 Jul 2019
    —
    Unknown

    CVE-2019-13368

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Jul 2019
    —
    Unknown

    CVE-2019-13367

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-12926

    Last Modified: 21 Nov 2024

    MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a number of actions, when logged in as a user, that that user should not have had permission to perform. It was also possible to gain access to areas within the application for which the accounts used were supposed to have insufficient access.

    Published: 8 Jul 2019
    8.1
    High

    CVE-2019-12925

    Last Modified: 21 Nov 2024

    MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This could lead to reading other users' credentials including those of SYSADMIN accounts, reading other users' emails, or adding emails or files to other users' accounts.

    Published: 8 Jul 2019
    9.8
    Critical

    CVE-2019-12924

    Last Modified: 21 Nov 2024

    MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user. It was possible for an attacker to use a vulnerability in the configuration of the XML processor to read any file on the host system. Because all credentials were stored in a cleartext file, it was possible to steal all users' credentials (including the highest privileged users).

    Published: 8 Jul 2019
    6.5
    Medium

    CVE-2019-12923

    Last Modified: 21 Nov 2024

    In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was possible to bypass it by removing the anti-CSRF token parameter from the request. This could allow an attacker to manipulate a user into unwittingly performing actions within the application (such as sending email, adding contacts, or changing settings) on behalf of the attacker.

    Published: 8 Jul 2019
    6.1
    Medium

    CVE-2019-12930

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web script or HTML via the method parameter.

    Published: 8 Jul 2019
    7.5
    High

    CVE-2019-9630

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.

    Published: 8 Jul 2019
    9.8
    Critical

    CVE-2019-9629

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

    Published: 8 Jul 2019
    5.5
    Medium

    CVE-2019-2119

    Last Modified: 21 Nov 2024

    In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This could lead to local information disclosure of protected data with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-131622568.

    Published: 8 Jul 2019
    5.5
    Medium

    CVE-2019-2118

    Last Modified: 21 Nov 2024

    In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-130161842.

    Published: 8 Jul 2019
    5.5
    Medium

    CVE-2019-2117

    Last Modified: 21 Nov 2024

    In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier systems with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-124107808.

    Published: 8 Jul 2019
    7.5
    High

    CVE-2019-2116

    Last Modified: 21 Nov 2024

    In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-117105007.

    Published: 8 Jul 2019
    5.5
    Medium

    CVE-2019-2113

    Last Modified: 21 Nov 2024

    In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset protection bypass with no additional privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122597079.

    Published: 8 Jul 2019
    7.8
    High

    CVE-2019-2112

    Last Modified: 21 Nov 2024

    In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-117997080.

    Published: 8 Jul 2019
    9.8
    Critical

    CVE-2019-2111

    Last Modified: 21 Nov 2024

    In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122856181.

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-2109

    Last Modified: 21 Nov 2024

    In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1. Android ID: A-130651570.

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-2107

    Last Modified: 21 Nov 2024

    In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-130024844.

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-2106

    Last Modified: 21 Nov 2024

    In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-130023983.

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-2105

    Last Modified: 21 Nov 2024

    In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-116114182.

    Published: 8 Jul 2019
    5.5
    Medium

    CVE-2019-2104

    Last Modified: 21 Nov 2024

    In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-131356202

    Published: 8 Jul 2019
    7.2
    High

    CVE-2019-10973

    Last Modified: 21 Nov 2024

    Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.

    Published: 8 Jul 2019
    9.8
    Critical

    CVE-2019-13354

    Last Modified: 21 Nov 2024

    The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6.

    Published: 8 Jul 2019
    6.1
    Medium

    CVE-2019-13414

    Last Modified: 21 Nov 2024

    The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php.

    Published: 8 Jul 2019
    9.8
    Critical

    CVE-2019-13413

    Last Modified: 21 Nov 2024

    The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.

    Published: 8 Jul 2019
    7.8
    High

    CVE-2019-12174

    Last Modified: 21 Nov 2024

    hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configFilePath:configFileName method of the me_hide_vpnhelper.Helper class in the me.hide.vpnhelper macOS privilege helper tool. This method takes user-supplied input and can be used to escalate privileges, as well as obtain the ability to run any application on the system in the root context.

    Published: 8 Jul 2019
    7.8
    High

    CVE-2019-12171

    Last Modified: 21 Nov 2024

    Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.

    Published: 8 Jul 2019
    4.6
    Medium

    CVE-2018-11563

    Last Modified: 21 Nov 2024

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS customer panel application.

    Published: 8 Jul 2019
    7.8
    High

    CVE-2019-13404

    Last Modified: 21 Nov 2024

    The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-13402

    Last Modified: 21 Nov 2024

    /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of services is reset.

    Published: 8 Jul 2019
    8.8
    High

    CVE-2019-13401

    Last Modified: 21 Nov 2024

    Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/.

    Published: 8 Jul 2019
    9.8
    Critical

    CVE-2019-13400

    Last Modified: 21 Nov 2024

    Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.

    Published: 8 Jul 2019
    5.9
    Medium

    CVE-2019-13399

    Last Modified: 21 Nov 2024

    Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversation.

    Published: 8 Jul 2019
    7.2
    High

    CVE-2019-13398

    Last Modified: 21 Nov 2024

    Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CGI script, as demonstrated by sed injection in cgi-bin/camctrl_save_profile.cgi (save parameter) and cgi-bin/ddns.cgi.

    Published: 8 Jul 2019
    5.4
    Medium

    CVE-2019-3889

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.

    Published: 8 Jul 2019