CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2019-5965

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 5 Jul 2019
    5.4
    Medium

    CVE-2019-5966

    Last Modified: 21 Nov 2024

    Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose the information via unspecified vectors.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2019-5969

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2019-5970

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5971

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2019-5972

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5973

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5974

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5979

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-5960

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 5 Jul 2019
    9.8
    Critical

    CVE-2019-13144

    Last Modified: 21 Nov 2024

    myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13312

    Last Modified: 21 Nov 2024

    block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.

    Published: 5 Jul 2019
    6.5
    Medium

    CVE-2019-13311

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.

    Published: 5 Jul 2019
    6.5
    Medium

    CVE-2019-13310

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.

    Published: 5 Jul 2019
    6.5
    Medium

    CVE-2019-13309

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13308

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-13307

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-13306

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-13305

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-13304

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13303

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13302

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages.

    Published: 5 Jul 2019
    6.5
    Medium

    CVE-2019-13301

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13300

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13299

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13298

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/pixel-accessor.h in SetPixelViaPixelInfo because of a MagickCore/enhance.c error.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13297

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.

    Published: 5 Jul 2019
    6.5
    Medium

    CVE-2019-13296

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has direct memory leaks in AcquireMagickMemory because of an error in CLIListOperatorImages in MagickWand/operation.c for a NULL value.

    Published: 5 Jul 2019
    8.8
    High

    CVE-2019-13295

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

    Published: 5 Jul 2019
    6.1
    Medium

    CVE-2019-13345

    Last Modified: 21 Nov 2024

    The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-2201

    Last Modified: 21 Nov 2024

    In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338

    Published: 5 Jul 2019
    7.8
    High

    CVE-2019-13313

    Last Modified: 21 Nov 2024

    libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

    Published: 5 Jul 2019
    9.8
    Critical

    CVE-2019-13294

    Last Modified: 21 Nov 2024

    AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.

    Published: 4 Jul 2019
    9.8
    Critical

    CVE-2019-13292

    Last Modified: 21 Nov 2024

    A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

    Published: 4 Jul 2019
    5.5
    Medium

    CVE-2019-13291

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Disclosure.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13290

    Last Modified: 21 Nov 2024

    Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13289

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool.

    Published: 4 Jul 2019
    5.5
    Medium

    CVE-2019-13288

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. This is similar to CVE-2018-16646.

    Published: 4 Jul 2019
    5.5
    Medium

    CVE-2019-13287

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to CVE-2018-16368.

    Published: 4 Jul 2019
    5.5
    Medium

    CVE-2019-13286

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure.

    Published: 4 Jul 2019
    6.5
    Medium

    CVE-2019-1890

    Last Modified: 21 Nov 2024

    A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. The vulnerability is due to insufficient security requirements during the Link Layer Discovery Protocol (LLDP) setup phase of the infrastructure VLAN. An attacker could exploit this vulnerability by sending a malicious LLDP packet on the adjacent subnet to the Cisco Nexus 9000 Series Switch in ACI mode. A successful exploit could allow the attacker to connect an unauthorized server to the infrastructure VLAN, which is highly privileged. With a connection to the infrastructure VLAN, the attacker can make unauthorized connections to Cisco Application Policy Infrastructure Controller (APIC) services or join other host endpoints.

    Published: 4 Jul 2019
    7.2
    High

    CVE-2019-1889

    Last Modified: 21 Nov 2024

    A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an affected device. The vulnerability is due to incomplete validation and error checking for the file path when specific software is uploaded. An attacker could exploit this vulnerability by uploading malicious software using the REST API. A successful exploit could allow an attacker to escalate their privilege level to root. The attacker would need to have the administrator role on the device.

    Published: 4 Jul 2019
    7.3
    High

    CVE-2019-1855

    Last Modified: 21 Nov 2024

    A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of the resources loaded by the application at run time. An attacker could exploit this vulnerability by crafting a malicious DLL file and placing it in a specific location on the targeted system. The malicious DLL file would execute when the Jabber application launches. A successful exploit could allow the attacker to execute arbitrary code on the target machine with the privileges of another user's account.

    Published: 4 Jul 2019
    7.7
    High

    CVE-2019-1884

    Last Modified: 21 Nov 2024

    A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation mechanisms for certain fields in HTTP/HTTPS requests sent through an affected device. A successful attacker could exploit this vulnerability by sending a malicious HTTP/HTTPS request through an affected device. An exploit could allow the attacker to force the device to stop processing traffic, resulting in a DoS condition.

    Published: 4 Jul 2019
    8.6
    High

    CVE-2019-1886

    Last Modified: 21 Nov 2024

    A vulnerability in the HTTPS decryption feature of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of Secure Sockets Layer (SSL) server certificates. An attacker could exploit this vulnerability by installing a malformed certificate in a web server and sending a request to it through the Cisco WSA. A successful exploit could allow the attacker to cause an unexpected restart of the proxy process on an affected device.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13283

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13282

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly have unspecified other impact.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13281

    Last Modified: 21 Nov 2024

    In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an information leak, or possibly unspecified other impact.

    Published: 4 Jul 2019
    9.8
    Critical

    CVE-2019-13275

    Last Modified: 21 Nov 2024

    An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13262

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.

    Published: 4 Jul 2019