CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2019-1623

    Last Modified: 21 Nov 2024

    A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability by injecting crafted arguments during command execution. A successful exploit could allow the attacker to perform arbitrary code execution as root on an affected product.

    Published: 20 Jun 2019
    8.8
    High

    CVE-2019-10164

    Last Modified: 21 Nov 2024

    PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

    Published: 20 Jun 2019
    9.8
    Critical

    CVE-2019-10747

    Last Modified: 21 Nov 2024

    set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.

    Published: 20 Jun 2019
    6.1
    Medium

    CVE-2019-13038

    Last Modified: 21 Nov 2024

    mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

    Published: 20 Jun 2019
    10
    Critical

    CVE-2019-11708

    Last Modified: 27 Oct 2025

    Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

    Published: 20 Jun 2019
    5.9
    Medium

    CVE-2019-12904

    Last Modified: 21 Nov 2024

    In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack

    Published: 19 Jun 2019
    4.3
    Medium

    CVE-2019-12903

    Last Modified: 21 Nov 2024

    Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-12902

    Last Modified: 21 Nov 2024

    Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a new user, holding the same User ID as a deleted user, to restore the deleted user's data.

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-12901

    Last Modified: 21 Nov 2024

    Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation.

    Published: 19 Jun 2019
    8.3
    High

    CVE-2019-3787

    Last Modified: 21 Nov 2024

    Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the attacker to gain complete control of the user's account.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-3737

    Last Modified: 21 Nov 2024

    Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-2729

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-12900

    Last Modified: 9 Jun 2025

    BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-12899

    Last Modified: 21 Nov 2024

    Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at ntdll!RtlQueueWorkItem+0x00000000000005e3.

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-12898

    Last Modified: 21 Nov 2024

    Delta Electronics DeviceNet Builder 2.04 has a User Mode Write AV starting at image00400000+0x000000000017a45e.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-12897

    Last Modified: 21 Nov 2024

    Edraw Max 7.9.3 has a Read Access Violation at the Instruction Pointer after a call from ObjectModule!Paint::Clear+0x0000000000000074.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-12896

    Last Modified: 21 Nov 2024

    Edraw Max 7.9.3 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a77.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-12895

    Last Modified: 21 Nov 2024

    In Alternate Pic View 2.600, the Exception Handler Chain is Corrupted starting at PicViewer!PerfgrapFinalize+0x00000000000b916d.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-12894

    Last Modified: 21 Nov 2024

    Alternate Pic View 2.600 has a Read Access Violation at the Instruction Pointer after a call from PicViewer!PerfgrapFinalize+0x00000000000a9a1b.

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-12893

    Last Modified: 21 Nov 2024

    Alternate Pic View 2.600 has a User Mode Write AV starting at PicViewer!PerfgrapFinalize+0x00000000000a8868.

    Published: 19 Jun 2019
    6.1
    Medium

    CVE-2017-14395

    Last Modified: 21 Nov 2024

    Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser via reflected XSS.

    Published: 19 Jun 2019
    6.1
    Medium

    CVE-2017-14394

    Last Modified: 21 Nov 2024

    OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-9561

    Last Modified: 21 Nov 2024

    In llcp_util_parse_connect of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-111660010

    Published: 19 Jun 2019
    7.8
    High

    CVE-2019-2023

    Last Modified: 21 Nov 2024

    In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in a privileged process.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-121035042Upstream kernel

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2003

    Last Modified: 21 Nov 2024

    In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-116321860

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-2022

    Last Modified: 21 Nov 2024

    In rw_t3t_act_handle_fmt_rsp and rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120506143

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-2021

    Last Modified: 21 Nov 2024

    In rw_t3t_act_handle_ndef_detect_rsp of rw_t3t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120428041

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-2020

    Last Modified: 21 Nov 2024

    In llcp_dlc_proc_rr_rnr_pdu of llcp_dlc.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-116788646

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2019-2019

    Last Modified: 21 Nov 2024

    In ce_t4t_data_cback of ce_t4t.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-115635871

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-9564

    Last Modified: 21 Nov 2024

    In llcp_util_parse_link_params of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-114238578

    Published: 19 Jun 2019
    6.5
    Medium

    CVE-2018-9563

    Last Modified: 21 Nov 2024

    In llcp_util_parse_cc of llcp_util.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-114237888

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2018

    Last Modified: 21 Nov 2024

    In resetPasswordInternal of DevicePolicyManagerService.java, there is a possible bypass of password reset protection due to an unusual root cause. Remote user interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-110172241

    Published: 19 Jun 2019
    7.8
    High

    CVE-2019-2017

    Last Modified: 21 Nov 2024

    In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-121035711

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2016

    Last Modified: 21 Nov 2024

    In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120664978

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2015

    Last Modified: 21 Nov 2024

    In rw_t3t_act_handle_check_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120503926

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2014

    Last Modified: 21 Nov 2024

    In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120499324

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2013

    Last Modified: 21 Nov 2024

    In rw_t3t_act_handle_sro_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120497583

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2012

    Last Modified: 21 Nov 2024

    In rw_t3t_act_handle_fmt_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120497437

    Published: 19 Jun 2019
    7.8
    High

    CVE-2019-2011

    Last Modified: 21 Nov 2024

    In readNullableNativeHandleNoDup of Parcel.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-120084106

    Published: 19 Jun 2019
    7.8
    High

    CVE-2019-2010

    Last Modified: 21 Nov 2024

    In phNxpNciHal_process_ext_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-118152591

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2009

    Last Modified: 21 Nov 2024

    In l2c_lcc_proc_pdu of l2c_fcr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-120665616

    Published: 19 Jun 2019
    7.5
    High

    CVE-2019-2008

    Last Modified: 21 Nov 2024

    In createEffect of AudioFlinger.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-122309228

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-2007

    Last Modified: 21 Nov 2024

    In getReadIndex and getWriteIndex of FifoControllerBase.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9Android ID: A-120789744

    Published: 19 Jun 2019
    9.8
    Critical

    CVE-2019-2006

    Last Modified: 21 Nov 2024

    In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-116665972

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-1990

    Last Modified: 21 Nov 2024

    In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-118453553

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-1989

    Last Modified: 21 Nov 2024

    In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-118399205

    Published: 19 Jun 2019
    8.8
    High

    CVE-2019-2005

    Last Modified: 21 Nov 2024

    In onPermissionGrantResult of GrantPermissionsActivity.java, there is a possible incorrectly granted permission due to a missing permission check. This could lead to local escalation of privilege on a locked device with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-68777217

    Published: 19 Jun 2019
    5.5
    Medium

    CVE-2019-2004

    Last Modified: 21 Nov 2024

    In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android ID: A-115739809

    Published: 19 Jun 2019
    7.8
    High

    CVE-2019-1985

    Last Modified: 21 Nov 2024

    In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0Android ID: A-118694079

    Published: 19 Jun 2019
    8.8
    High

    CVE-2018-16593

    Last Modified: 21 Nov 2024

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.

    Published: 19 Jun 2019