CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-13390

    Last Modified: 21 Nov 2024

    In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c.

    Published: 7 Jul 2019
    8.8
    High

    CVE-2019-13379

    Last Modified: 21 Nov 2024

    On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

    Published: 7 Jul 2019
    8.8
    High

    CVE-2019-13183

    Last Modified: 21 Nov 2024

    Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.

    Published: 7 Jul 2019
    9.8
    Critical

    CVE-2019-13375

    Last Modified: 21 Nov 2024

    A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php with the index.php/Pay/passcodeAuth parameter passcode. The vulnerability does not need any authentication.

    Published: 6 Jul 2019
    6.1
    Medium

    CVE-2019-13374

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.

    Published: 6 Jul 2019
    9.8
    Critical

    CVE-2019-13373

    Last Modified: 21 Nov 2024

    An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validated and arbitrary SQL statements can be executed in the database via the /web/Public/Conn.php parameter dbSQL.

    Published: 6 Jul 2019
    9.8
    Critical

    CVE-2019-13372

    Last Modified: 21 Nov 2024

    /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie's username field allows eval injection, and an empty password bypasses authentication.

    Published: 6 Jul 2019
    8.8
    High

    CVE-2019-13370

    Last Modified: 21 Nov 2024

    index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.

    Published: 6 Jul 2019
    7.8
    High

    CVE-2019-13362

    Last Modified: 21 Nov 2024

    Codedoc v3.2 has a stack-based buffer overflow in add_variable in codedoc.c, related to codedoc_strlcpy.

    Published: 6 Jul 2019
    6.1
    Medium

    CVE-2019-1930

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 6 Jul 2019
    6.1
    Medium

    CVE-2019-1931

    Last Modified: 26 Nov 2024

    Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected device. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

    Published: 6 Jul 2019
    6.7
    Medium

    CVE-2019-1932

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local attacker with administrator privileges to execute arbitrary code. The vulnerability is due to insufficient validation of dynamically loaded modules. An attacker could exploit this vulnerability by placing a file in a specific location in the Windows filesystem. A successful exploit could allow the attacker to execute the code with the privileges of the AMP service.

    Published: 6 Jul 2019
    5.8
    Medium

    CVE-2019-1933

    Last Modified: 21 Nov 2024

    A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured filters on the device. The vulnerability is due to improper input validation of certain email fields. An attacker could exploit this vulnerability by sending a crafted email message to a recipient protected by the ESA. A successful exploit could allow the attacker to bypass configured message filters and inject arbitrary scripting code inside the email body. The malicious code is not executed by default unless the recipient's email client is configured to execute scripts contained in emails.

    Published: 6 Jul 2019
    5.8
    Medium

    CVE-2019-1921

    Last Modified: 21 Nov 2024

    A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper input validation of the email body. An attacker could exploit this vulnerability by naming a malicious attachment with a specific pattern. A successful exploit could allow the attacker to bypass configured content filters that would normally block the attachment.

    Published: 6 Jul 2019
    5.3
    Medium

    CVE-2019-1922

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation of input Session Initiation Protocol (SIP) packets. An attacker could exploit this vulnerability by altering the SIP replies that are sent to the affected phone during the registration process. A successful exploit could allow the attacker to cause the phone to reboot and not complete the registration process.

    Published: 6 Jul 2019
    7.8
    High

    CVE-2019-1893

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient input validation of a configuration file that is accessible to a local shell user. An attacker could exploit this vulnerability by including malicious input during the execution of this file. A successful exploit could allow the attacker to execute arbitrary commands on the underlying OS as root.

    Published: 6 Jul 2019
    7.2
    High

    CVE-2019-1894

    Last Modified: 21 Nov 2024

    A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite or read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in NFVIS filesystem commands. An attacker could exploit this vulnerability by using crafted variables during the execution of an affected command. A successful exploit could allow the attacker to overwrite or read arbitrary files on the underlying OS.

    Published: 6 Jul 2019
    6.8
    Medium

    CVE-2019-1909

    Last Modified: 21 Nov 2024

    A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect processing of certain BGP update messages. An attacker could exploit this vulnerability by sending BGP update messages that include a specific set of attributes to be processed by an affected system. A successful exploit could allow the attacker to cause the BGP process to restart unexpectedly, resulting in a DoS condition. The Cisco implementation of BGP accepts incoming BGP traffic from explicitly defined peers only. To exploit this vulnerability, the malicious BGP update message would need to come from a configured, valid BGP peer or would need to be injected by the attacker into the victim's BGP network on an existing, valid TCP connection to a BGP peer.

    Published: 6 Jul 2019
    5.3
    Medium

    CVE-2019-1911

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell commands. An attacker could exploit this vulnerability by executing crafted commands in the shell. A successful exploit could allow the attacker to escape the restricted shell and access commands in the context of the restricted shell user, which does not have root privileges.

    Published: 6 Jul 2019
    8.6
    High

    CVE-2019-1887

    Last Modified: 21 Nov 2024

    A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of input SIP traffic. An attacker could exploit this vulnerability by sending a malformed SIP packet to an affected Cisco Unified Communications Manager. A successful exploit could allow the attacker to trigger a new registration process on all connected phones, temporarily disrupting service.

    Published: 6 Jul 2019
    7.5
    High

    CVE-2019-1891

    Last Modified: 21 Nov 2024

    A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of requests sent to the web interface. An attacker could exploit this vulnerability by sending a malicious request to the web interface of an affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a DoS condition.

    Published: 6 Jul 2019
    7.5
    High

    CVE-2019-1892

    Last Modified: 21 Nov 2024

    A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an unauthenticated, remote attacker to cause a memory corruption on an affected device. The vulnerability is due to improper validation of HTTPS packets. An attacker could exploit this vulnerability by sending a malformed HTTPS packet to the management web interface of the affected device. A successful exploit could allow the attacker to cause an unexpected reload of the device, resulting in a denial of service (DoS) condition.

    Published: 6 Jul 2019
    7.5
    High

    CVE-2019-10639

    Last Modified: 21 Nov 2024

    The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclosure), leading to a KASLR bypass. Specifically, it is possible to extract the KASLR kernel image offset using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). This key contains enough bits from a kernel address (of a static variable) so when the key is extracted (via enumeration), the offset of the kernel image is exposed. This attack can be carried out remotely, by the attacker forcing the target device to send UDP or ICMP (or certain other) traffic to attacker-controlled IP addresses. Forcing a server to send UDP traffic is trivial if the server is a DNS server. ICMP traffic is trivial if the server answers ICMP Echo requests (ping). For client targets, if the target visits the attacker's web page, then WebRTC or gQUIC can be used to force UDP traffic to attacker-controlled IP addresses. NOTE: this attack against KASLR became viable in 4.1 because IP ID generation was changed to have a dependency on an address associated with a network namespace.

    Published: 5 Jul 2019
    6.5
    Medium

    CVE-2019-10638

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g., UDP and ICMP). When such traffic is sent to multiple destination IP addresses, it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may be conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses.

    Published: 5 Jul 2019
    7.5
    High

    CVE-2019-13358

    Last Modified: 21 Nov 2024

    lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker must upload a file in the docx or odt format.

    Published: 5 Jul 2019
    7.5
    High

    CVE-2018-16386

    Last Modified: 21 Nov 2024

    An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.

    Published: 5 Jul 2019
    7.5
    High

    CVE-2018-14733

    Last Modified: 21 Nov 2024

    The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.

    Published: 5 Jul 2019
    7.5
    High

    CVE-2018-14529

    Last Modified: 21 Nov 2024

    Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.

    Published: 5 Jul 2019
    9.8
    Critical

    CVE-2018-14528

    Last Modified: 21 Nov 2024

    Invoxia NVX220 devices allow TELNET access as admin with a default password.

    Published: 5 Jul 2019
    9.8
    Critical

    CVE-2019-12971

    Last Modified: 21 Nov 2024

    BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.

    Published: 5 Jul 2019
    9.8
    Critical

    CVE-2019-13352

    Last Modified: 21 Nov 2024

    WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access.

    Published: 5 Jul 2019
    8.1
    High

    CVE-2019-13351

    Last Modified: 21 Nov 2024

    posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2018-12621

    Last Modified: 21 Nov 2024

    An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2018-14027

    Last Modified: 21 Nov 2024

    Digisol Wireless Wifi Home Router HR-3300 allows XSS via the userid or password parameter to the admin login page.

    Published: 5 Jul 2019
    5.3
    Medium

    CVE-2019-13344

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

    Published: 5 Jul 2019
    4.8
    Medium

    CVE-2019-13341

    Last Modified: 21 Nov 2024

    In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.

    Published: 5 Jul 2019
    4.8
    Medium

    CVE-2019-13340

    Last Modified: 21 Nov 2024

    In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.

    Published: 5 Jul 2019
    4.8
    Medium

    CVE-2019-13339

    Last Modified: 21 Nov 2024

    In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-13314

    Last Modified: 21 Nov 2024

    virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py.

    Published: 5 Jul 2019
    7.5
    High

    CVE-2019-5982

    Last Modified: 21 Nov 2024

    Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A successful exploitation may result in a malicious file being downloaded/executed.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5983

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5984

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5968

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authentication of administrators via updating user's 'Basic Info'.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-5981

    Last Modified: 21 Nov 2024

    Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary executable file with administrative privilege via unspecified vectors.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2019-5967

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5980

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    7.4
    High

    CVE-2019-5961

    Last Modified: 21 Nov 2024

    The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2019-5962

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5963

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5964

    Last Modified: 21 Nov 2024

    iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the management console and operate the product via unspecified vectors.

    Published: 5 Jul 2019