CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-13261

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13260

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13259

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e566.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13258

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328165.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13257

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003273aa.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13256

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e849.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13255

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327464.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13254

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000032e808.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13253

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000385474.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13252

    Last Modified: 21 Nov 2024

    ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000001172b0.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13251

    Last Modified: 21 Nov 2024

    ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000c47ff.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13250

    Last Modified: 21 Nov 2024

    ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9c2f.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13249

    Last Modified: 21 Nov 2024

    ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!IEP_SetColorProfile+0x00000000000b9e7a.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13248

    Last Modified: 21 Nov 2024

    ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x0000000000002450.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13247

    Last Modified: 21 Nov 2024

    ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000024ed.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13246

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a9601.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13245

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x00000000001a95b1.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13244

    Last Modified: 21 Nov 2024

    FastStone Image Viewer 7.0 has a User Mode Write AV starting at image00400000+0x0000000000002d7d.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13243

    Last Modified: 21 Nov 2024

    IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x00000000000249c6.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13242

    Last Modified: 21 Nov 2024

    IrfanView 4.52 has a User Mode Write AV starting at image00400000+0x0000000000013a98.

    Published: 4 Jul 2019
    7.8
    High

    CVE-2019-13241

    Last Modified: 21 Nov 2024

    FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.

    Published: 4 Jul 2019
    6.1
    Medium

    CVE-2019-13239

    Last Modified: 21 Nov 2024

    inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.

    Published: 4 Jul 2019
    7.5
    High

    CVE-2019-13238

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1.0. A memory allocation failure is unhandled in Core/Ap4SdpAtom.cpp and leads to crashes. When parsing input video, the program allocates a new buffer to parse an atom in the stream. The unhandled memory allocation failure causes a direct copy to a NULL pointer.

    Published: 4 Jul 2019
    8.2
    High

    CVE-2018-20850

    Last Modified: 21 Nov 2024

    Stormshield Network Security 2.0.0 through 2.13.0 and 3.0.0 through 3.7.1 has self-XSS in the command line interface of the SNS web server.

    Published: 4 Jul 2019
    5.5
    Medium

    CVE-2019-13229

    Last Modified: 21 Nov 2024

    deepin-clone before 1.1.3 uses a fixed path /tmp/partclone.log in the Helper::getPartitionSizeInfo() function to write a log file as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.

    Published: 4 Jul 2019
    4.7
    Medium

    CVE-2019-13228

    Last Modified: 21 Nov 2024

    deepin-clone before 1.1.3 uses a fixed path /tmp/repo.iso in the BootDoctor::fix() function to download an ISO file, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled. By winning a race condition to replace the /tmp/repo.iso symlink by an attacker controlled ISO file, further privilege escalation may be possible.

    Published: 4 Jul 2019
    5.5
    Medium

    CVE-2019-13227

    Last Modified: 21 Nov 2024

    In GUI mode, deepin-clone before 1.1.3 creates a log file at the fixed path /tmp/.deepin-clone.log as root, and follows symlinks there. An unprivileged user can prepare a symlink attack there to create or overwrite files in arbitrary file system locations. The content is not attacker controlled.

    Published: 4 Jul 2019
    7
    High

    CVE-2019-13226

    Last Modified: 21 Nov 2024

    deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.

    Published: 4 Jul 2019
    6.1
    Medium

    CVE-2019-18348

    Last Modified: 21 Nov 2024

    An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.

    Published: 4 Jul 2019
    7
    High

    CVE-2019-13233

    Last Modified: 21 Nov 2024

    In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

    Published: 4 Jul 2019
    7.3
    High

    CVE-2019-13208

    Last Modified: 21 Nov 2024

    WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading. This affects WavesSysSvc64.exe 1.9.29.0.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2015-3907

    Last Modified: 21 Nov 2024

    CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2019-13074

    Last Modified: 21 Nov 2024

    A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-13207

    Last Modified: 21 Nov 2024

    nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-12852

    Last Modified: 21 Nov 2024

    An SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.

    Published: 3 Jul 2019
    4.3
    Medium

    CVE-2019-12846

    Last Modified: 21 Nov 2024

    A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2019-12842

    Last Modified: 21 Nov 2024

    A reflected XSS on a user page was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.2.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2019-12841

    Last Modified: 21 Nov 2024

    Incorrect handling of user input in ZIP extraction was detected in JetBrains TeamCity. The issue was fixed in TeamCity 2018.2.2.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2019-12843

    Last Modified: 21 Nov 2024

    A possible stored JavaScript injection requiring a deliberate server administrator action was detected. The issue was fixed in JetBrains TeamCity 2018.2.3.

    Published: 3 Jul 2019
    5.3
    Medium

    CVE-2019-12845

    Last Modified: 21 Nov 2024

    The generated Kotlin DSL settings allowed usage of an unencrypted connection for resolving artifacts. The issue was fixed in JetBrains TeamCity 2018.2.3.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2019-12844

    Last Modified: 21 Nov 2024

    A possible stored JavaScript injection was detected on one of the JetBrains TeamCity pages. The issue was fixed in TeamCity 2018.2.3.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2017-13719

    Last Modified: 21 Nov 2024

    The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of the web management interface that is provided by the application. This HTTP API receives the credentials as base64 encoded in the Authorization HTTP header. However, a missing length check in the code allows an attacker to send a string of 1024 characters in the password field, and allows an attacker to exploit a memory corruption issue. This can allow an attacker to circumvent the account protection mechanism and brute force the credentials. If the firmware version Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 is dissected using the binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that has many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that performs the credential check in the binary for the HTTP API specification. If we open this binary in IDA Pro we will notice that this follows an ARM little-endian format. The function at address 00415364 in IDA Pro starts the HTTP authentication process. This function calls another function at sub_ 0042CCA0 at address 0041549C. This function performs a strchr operation after base64 decoding the credentials, and stores the result on the stack, which results in a stack-based buffer overflow.

    Published: 3 Jul 2019
    8.8
    High

    CVE-2017-8228

    Last Modified: 21 Nov 2024

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that the user actually owns the camera other than knowing the serial number of the camera. This can allow an attacker who knows the serial number to easily add another user's camera to an attacker's cloud account and control it completely. This is possible in case of any camera that is currently not a part of an Amcrest cloud account or has been removed from the user's cloud account. Also, another requirement for a successful attack is that the user should have rebooted the camera in the last two hours. However, both of these conditions are very likely for new cameras that are sold over the Internet at many ecommerce websites or vendors that sell the Amcrest products. The successful attack results in an attacker being able to completely control the camera which includes being able to view and listen on what the camera can see, being able to change the motion detection settings and also be able to turn the camera off without the user being aware of it. Note: The same attack can be executed using the Amcrest Cloud mobile application.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2017-8227

    Last Modified: 21 Nov 2024

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API interface provided by the device. However, if the same brute force attempt is performed using the ONVIF specification (which is supported by the same binary) then there is no account lockout or timeout executed. This can allow an attacker to circumvent the account protection mechanism and brute force the credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that performs the credential check in the binary for the ONVIF specification. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function at address 00671618 in IDA pro is parses the WSSE security token header. The sub_ 603D8 then performs the authentication check and if it is incorrect passes to the function sub_59F4C which prints the value "Sender not authorized."

    Published: 3 Jul 2019
    8.8
    High

    CVE-2017-8230

    Last Modified: 21 Nov 2024

    On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identified that a low privileged user who belongs to the "user" group and who has access to login in to the web administrative interface of the device can add a new administrative user to the interface using HTTP APIs provided by the device and perform all the actions as an administrative user by using that account. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable functions that performs the various action described in HTTP APIs. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function at address 0x00429084 in IDA pro is the one that processes the HTTP API request for "addUser" action. If one traces the calls to this function, it can be clearly seen that the function sub_ 41F38C at address 0x0041F588 parses the call received from the browser and passes it to the "addUser" function without any authorization check.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2017-8226

    Last Modified: 21 Nov 2024

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro, one will notice that this follows a ARM little endian format. The function sub_3DB2FC in IDA pro is identified to be setting up the values at address 0x003DB5A6. The sub_5C057C then sets this value and adds it to the Configuration files in /mnt/mtd/Config/Account1 file.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2017-8229

    Last Modified: 21 Nov 2024

    Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function sub_436D6 in IDA pro is identified to be setting up the configuration for the device. If one scrolls to the address 0x000437C2 then one can see that /current_config is being set as an ALIAS for /mnt/mtd/Config folder on the device. If one TELNETs into the device and navigates to /mnt/mtd/Config folder, one can observe that it contains various files such as Account1, Account2, SHAACcount1, etc. This means that if one navigates to http://[IPofcamera]/current_config/Sha1Account1 then one should be able to view the content of the files. The security researchers assumed that this was only possible only after authentication to the device. However, when unauthenticated access tests were performed for the same URL as provided above, it was observed that the device file could be downloaded without any authentication.

    Published: 3 Jul 2019
    8.1
    High

    CVE-2018-14859

    Last Modified: 21 Nov 2024

    Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token.

    Published: 3 Jul 2019
    9.1
    Critical

    CVE-2018-14860

    Last Modified: 21 Nov 2024

    Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2018-14861

    Last Modified: 21 Nov 2024

    Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.

    Published: 3 Jul 2019