CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-14862

    Last Modified: 21 Nov 2024

    Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.

    Published: 3 Jul 2019
    8.1
    High

    CVE-2018-14863

    Last Modified: 21 Nov 2024

    Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.

    Published: 3 Jul 2019
    8.8
    High

    CVE-2019-5602

    Last Modified: 21 Nov 2024

    In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite kernel memory when media is present thereby allowing a malicious user in the operator group to gain root privileges.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-10104

    Last Modified: 21 Nov 2024

    In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2019-5601

    Last Modified: 21 Nov 2024

    In FreeBSD 12.0-STABLE before r347474, 12.0-RELEASE before 12.0-RELEASE-p7, 11.2-STABLE before r347475, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the FFS implementation causes up to three bytes of kernel stack memory to be written to disk as uninitialized directory entry padding.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2018-14864

    Last Modified: 21 Nov 2024

    Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-5600

    Last Modified: 21 Nov 2024

    In FreeBSD 12.0-STABLE before r349622, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349624, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in iconv implementation may allow an attacker to write past the end of an output buffer. Depending on the implementation, an attacker may be able to create a denial of service, provoke incorrect program behavior, or induce a remote code execution.

    Published: 3 Jul 2019
    8.8
    High

    CVE-2019-5051

    Last Modified: 21 Nov 2024

    An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-9873

    Last Modified: 21 Nov 2024

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.

    Published: 3 Jul 2019
    8.8
    High

    CVE-2019-5052

    Last Modified: 21 Nov 2024

    An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2018-14865

    Last Modified: 21 Nov 2024

    Report engine in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier does not use secure options when passing documents to wkhtmltopdf, which allows remote attackers to read local files.

    Published: 3 Jul 2019
    8.1
    High

    CVE-2019-9872

    Last Modified: 21 Nov 2024

    In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-9186

    Last Modified: 21 Nov 2024

    In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2019-6641

    Last Modified: 21 Nov 2024

    On BIG-IP 12.1.0-12.1.4.1, undisclosed requests can cause iControl REST processes to crash. The attack can only come from an authenticated user; all roles are capable of performing the attack. Unauthenticated users cannot perform this attack.

    Published: 3 Jul 2019
    7.2
    High

    CVE-2019-12847

    Last Modified: 21 Nov 2024

    In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.

    Published: 3 Jul 2019
    5.3
    Medium

    CVE-2019-6640

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is inserted into various profile types and accessed using SNMPv2.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-12866

    Last Modified: 21 Nov 2024

    An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

    Published: 3 Jul 2019
    4.8
    Medium

    CVE-2019-6639

    Last Modified: 21 Nov 2024

    On BIG-IP (AFM, PEM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, an undisclosed TMUI pages for AFM and PEM Subscriber management are vulnerable to a stored cross-site scripting (XSS) issue. This is a control plane issue only and is not accessible from the data plane. The attack requires a malicious resource administrator to store the XSS.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-12867

    Last Modified: 21 Nov 2024

    Certain actions could cause privilege escalation for issue attachments in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2019-6638

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, Malformed http requests made to an undisclosed iControl REST endpoint can lead to infinite loop of the restjavad process.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-12850

    Last Modified: 21 Nov 2024

    A query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2019-6637

    Last Modified: 21 Nov 2024

    On BIG-IP (ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, Application logic abuse of ASM REST endpoints can lead to instability of BIG-IP system. Exploitation of this issue causes excessive memory consumption which results in the Linux kernel triggering OOM killer on arbitrary processes. The attack requires an authenticated user with role of "Guest" or greater privilege. Note: "No Access" cannot login so technically it's a role but a user with this access role cannot perform the attack.

    Published: 3 Jul 2019
    8.8
    High

    CVE-2019-12851

    Last Modified: 21 Nov 2024

    A CSRF vulnerability was detected in one of the admin endpoints of JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49852.

    Published: 3 Jul 2019
    8.4
    High

    CVE-2019-6636

    Last Modified: 21 Nov 2024

    On BIG-IP (AFM, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a stored cross-site scripting vulnerability in AFM feed list. In the worst case, an attacker can store a CSRF which results in code execution as the admin user. The level of user role which can perform this attack are resource administrator and administrator.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-10100

    Last Modified: 21 Nov 2024

    In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the link-text-template field to execute code remotely.

    Published: 3 Jul 2019
    6.5
    Medium

    CVE-2019-6634

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, a high volume of malformed analytics report requests leads to instability in restjavad process. This causes issues with both iControl REST and some portions of TMUI. The attack requires an authenticated user with any role.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-9823

    Last Modified: 21 Nov 2024

    In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.

    Published: 3 Jul 2019
    4.4
    Medium

    CVE-2019-6635

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, when the BIG-IP system is licensed for Appliance mode, a user with either the Administrator or the Resource Administrator role can bypass Appliance mode restrictions.

    Published: 3 Jul 2019
    5.5
    Medium

    CVE-2019-6632

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, under certain circumstances, attackers can decrypt configuration items that are encrypted because the vCMP configuration unit key is generated with insufficient randomness. The attack prerequisite is direct access to encrypted configuration and/or UCS files.

    Published: 3 Jul 2019
    4.4
    Medium

    CVE-2019-6633

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4.1, and 11.5.1-11.6.4, when the BIG-IP system is licensed with Appliance mode, user accounts with Administrator and Resource Administrator roles can bypass Appliance mode restrictions.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2019-6630

    Last Modified: 21 Nov 2024

    On F5 SSL Orchestrator 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, undisclosed traffic flow may cause TMM to restart under certain circumstances.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2019-6631

    Last Modified: 21 Nov 2024

    On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing traffic handled by a Virtual Server with an associated HTTP profile, in specific circumstances, when the requests do not strictly conform to RFCs.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2019-6629

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TMM to fail and restart. The Client SSL profile must have session tickets enabled and use DHE cipher suites to be affected. This only impacts the data plane, there is no impact to the control plane.

    Published: 3 Jul 2019
    5.9
    Medium

    CVE-2019-6627

    Last Modified: 21 Nov 2024

    On F5 SSL Orchestrator 14.1.0-14.1.0.5, on rare occasions, specific to a certain race condition, TMM may restart when SSL Forward Proxy enforces the bypass action for an SSL Orchestrator transparent virtual server with SNAT enabled.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2019-6628

    Last Modified: 21 Nov 2024

    On BIG-IP PEM 14.1.0-14.1.0.5 and 14.0.0-14.0.0.4, under certain conditions, the TMM process may terminate and restart while processing BIG-IP PEM traffic with the OpenVPN classifier.

    Published: 3 Jul 2019
    4.3
    Medium

    CVE-2018-14866

    Last Modified: 21 Nov 2024

    Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2019-6625

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.4, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI) also known as the BIG-IP Configuration utility.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2019-6626

    Last Modified: 21 Nov 2024

    On BIG-IP (AFM, Analytics, ASM) 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, and 11.5.1-11.6.3.4, A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Traffic Management User Interface (TMUI), also known as the Configuration utility.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2019-7165

    Last Modified: 21 Nov 2024

    A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.

    Published: 3 Jul 2019
    8.8
    High

    CVE-2019-12570

    Last Modified: 21 Nov 2024

    A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an authenticated user to execute arbitrary SQL commands via GET parameters.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2018-12715

    Last Modified: 21 Nov 2024

    DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.

    Published: 3 Jul 2019
    5.9
    Medium

    CVE-2019-5630

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.

    Published: 3 Jul 2019
    7.2
    High

    CVE-2018-12250

    Last Modified: 21 Nov 2024

    An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL injection.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2018-18326

    Last Modified: 21 Nov 2024

    DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2018-18325

    Last Modified: 7 Nov 2025

    DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2017-17972

    Last Modified: 21 Nov 2024

    packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.

    Published: 3 Jul 2019
    7.5
    High

    CVE-2018-15812

    Last Modified: 21 Nov 2024

    DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2017-18346

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.

    Published: 3 Jul 2019
    9.8
    Critical

    CVE-2018-11686

    Last Modified: 21 Nov 2024

    The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

    Published: 3 Jul 2019
    6.1
    Medium

    CVE-2017-6216

    Last Modified: 21 Nov 2024

    novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution

    Published: 3 Jul 2019