CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2019-13084

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739.

    Published: 30 Jun 2019
    7.8
    High

    CVE-2019-13083

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a.

    Published: 30 Jun 2019
    9.8
    Critical

    CVE-2019-13082

    Last Modified: 21 Nov 2024

    Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder in a ZIP archive, the server will accept this file without any checks. Because one can access this file from the website, it is remote code execution. This is related to a scorm imsmanifest.xml file, the import_package function, and extraction in $courseSysDir.$newDir.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-11827

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows remote attackers to inject arbitrary web script or HTML via the object_id parameter.

    Published: 30 Jun 2019
    5.5
    Medium

    CVE-2019-11828

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jun 2019
    7.3
    High

    CVE-2019-11829

    Last Modified: 21 Nov 2024

    OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.

    Published: 30 Jun 2019
    4.3
    Medium

    CVE-2019-11822

    Last Modified: 21 Nov 2024

    Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter.

    Published: 30 Jun 2019
    7.3
    High

    CVE-2019-11821

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to execute arbitrary SQL command via the type parameter.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-11825

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 30 Jun 2019
    8
    High

    CVE-2019-11826

    Last Modified: 21 Nov 2024

    Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.

    Published: 30 Jun 2019
    5.3
    Medium

    CVE-2019-13075

    Last Modified: 21 Nov 2024

    Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.

    Published: 30 Jun 2019
    5.4
    Medium

    CVE-2019-13072

    Last Modified: 21 Nov 2024

    Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript code in the browser of any user who navigates to this page.

    Published: 30 Jun 2019
    5.3
    Medium

    CVE-2019-13118

    Last Modified: 28 May 2026

    In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13109

    Last Modified: 21 Nov 2024

    An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13114

    Last Modified: 21 Nov 2024

    http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13110

    Last Modified: 21 Nov 2024

    A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.

    Published: 30 Jun 2019
    5.5
    Medium

    CVE-2019-13111

    Last Modified: 21 Nov 2024

    A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13112

    Last Modified: 21 Nov 2024

    A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13113

    Last Modified: 21 Nov 2024

    Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.

    Published: 30 Jun 2019
    5.3
    Medium

    CVE-2019-13117

    Last Modified: 28 May 2026

    In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13147

    Last Modified: 3 Nov 2025

    In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

    Published: 30 Jun 2019
    6.5
    Medium

    CVE-2019-13108

    Last Modified: 21 Nov 2024

    An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.

    Published: 30 Jun 2019
    9.8
    Critical

    CVE-2019-13067

    Last Modified: 21 Nov 2024

    njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

    Published: 29 Jun 2019
    6.5
    Medium

    CVE-2019-13055

    Last Modified: 21 Nov 2024

    Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency transmissions, as demonstrated by an attack against a Logitech K360 keyboard.

    Published: 29 Jun 2019
    6.5
    Medium

    CVE-2019-13054

    Last Modified: 21 Nov 2024

    The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.

    Published: 29 Jun 2019
    6.5
    Medium

    CVE-2019-13053

    Last Modified: 21 Nov 2024

    Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptographic data from a Radio Frequency transmission. NOTE: this issue exists because of an incomplete fix for CVE-2016-10761.

    Published: 29 Jun 2019
    6.5
    Medium

    CVE-2016-10761

    Last Modified: 21 Nov 2024

    Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

    Published: 29 Jun 2019
    6.5
    Medium

    CVE-2019-13052

    Last Modified: 21 Nov 2024

    Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.

    Published: 29 Jun 2019
    7.8
    High

    CVE-2019-13049

    Last Modified: 21 Nov 2024

    An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland process space via TOARU_SYS_FUNC_MMAP, leading to escalation of privileges.

    Published: 29 Jun 2019
    5.5
    Medium

    CVE-2019-13048

    Last Modified: 21 Nov 2024

    kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allocation patterns (involving PAGE_SIZE, and a value less than PAGE_SIZE).

    Published: 29 Jun 2019
    7.8
    High

    CVE-2019-13047

    Last Modified: 21 Nov 2024

    kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SETHEAP, allowing arbitrary kernel pages to be mapped into user land, leading to root access.

    Published: 29 Jun 2019
    7.8
    High

    CVE-2019-13046

    Last Modified: 21 Nov 2024

    linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications.

    Published: 29 Jun 2019
    —
    Unknown

    CVE-2019-13044

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Jun 2019
    7.8
    High

    CVE-2019-13035

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFMS and its sub-folders, allowing standard users to create new files. Moreover, the Apache service httpd.exe will try to execute cmd.exe from C:\PandoraFMS (the current directory) as NT AUTHORITY\SYSTEM upon web requests to the portal. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM.

    Published: 29 Jun 2019
    5.4
    Medium

    CVE-2019-13068

    Last Modified: 21 Nov 2024

    public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

    Published: 29 Jun 2019
    8.1
    High

    CVE-2019-13045

    Last Modified: 21 Nov 2024

    Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending SASL login to the server.

    Published: 29 Jun 2019
    7.5
    High

    CVE-2019-13050

    Last Modified: 21 Nov 2024

    Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.

    Published: 29 Jun 2019
    5.5
    Medium

    CVE-2019-13032

    Last Modified: 21 Nov 2024

    An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.

    Published: 28 Jun 2019
    8.1
    High

    CVE-2019-13031

    Last Modified: 21 Nov 2024

    LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.

    Published: 28 Jun 2019
    8.8
    High

    CVE-2019-13028

    Last Modified: 21 Nov 2024

    An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML page. This is a product from the Ministry of Interior of the Slovak Republic.

    Published: 28 Jun 2019
    7.1
    High

    CVE-2019-10964

    Last Modified: 22 May 2025

    Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.

    Published: 28 Jun 2019
    9.8
    Critical

    CVE-2019-10993

    Last Modified: 21 Nov 2024

    In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote attacker to execute arbitrary code.

    Published: 28 Jun 2019
    8.8
    High

    CVE-2019-10987

    Last Modified: 21 Nov 2024

    In WebAccess/SCADA Versions 8.3.5 and prior, multiple out-of-bounds write vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.

    Published: 28 Jun 2019
    7.5
    High

    CVE-2019-10983

    Last Modified: 21 Nov 2024

    In WebAccess/SCADA Versions 8.3.5 and prior, an out-of-bounds read vulnerability is caused by a lack of proper validation of user-supplied data. Exploitation of this vulnerability may allow disclosure of information.

    Published: 28 Jun 2019
    9.8
    Critical

    CVE-2019-10989

    Last Modified: 21 Nov 2024

    In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution. Note: A different vulnerability than CVE-2019-10991.

    Published: 28 Jun 2019
    9.8
    Critical

    CVE-2019-10991

    Last Modified: 21 Nov 2024

    In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length of user-supplied data. Exploitation of these vulnerabilities may allow remote code execution.

    Published: 28 Jun 2019
    9.1
    Critical

    CVE-2019-10985

    Last Modified: 21 Nov 2024

    In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage this vulnerability to delete files while posing as an administrator.

    Published: 28 Jun 2019
    8.1
    High

    CVE-2018-17170

    Last Modified: 21 Nov 2024

    Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.

    Published: 28 Jun 2019
    6.1
    Medium

    CVE-2018-17560

    Last Modified: 21 Nov 2024

    The admin interface of the Grouptime Teamwire Client 1.5.1 prior to 1.9.0 on-premises messenger server allows stored XSS. All backend versions prior to prod-2018-11-13-15-00-42 are affected.

    Published: 28 Jun 2019
    5.3
    Medium

    CVE-2018-14867

    Last Modified: 21 Nov 2024

    Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters.

    Published: 28 Jun 2019