CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-19465

    Last Modified: 21 Nov 2024

    Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.

    Published: 7 Jun 2019
    9.8
    Critical

    CVE-2018-19800

    Last Modified: 21 Nov 2024

    aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.

    Published: 7 Jun 2019
    7.5
    High

    CVE-2018-19801

    Last Modified: 21 Nov 2024

    aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.

    Published: 7 Jun 2019
    7.5
    High

    CVE-2018-19802

    Last Modified: 21 Nov 2024

    aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.

    Published: 7 Jun 2019
    8.8
    High

    CVE-2018-19860

    Last Modified: 21 Nov 2024

    Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.

    Published: 7 Jun 2019
    6.1
    Medium

    CVE-2019-3477

    Last Modified: 21 Nov 2024

    Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.

    Published: 7 Jun 2019
    7.8
    High

    CVE-2018-19999

    Last Modified: 21 Nov 2024

    The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.

    Published: 7 Jun 2019
    7.5
    High

    CVE-2018-20014

    Last Modified: 21 Nov 2024

    In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::GetFileHashAndMetadata NULL pointer dereference, leading to shutting down the client application.

    Published: 7 Jun 2019
    9.9
    Critical

    CVE-2018-20091

    Last Modified: 21 Nov 2024

    An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API keys, and stored Kerberos keytabs.

    Published: 7 Jun 2019
    8.1
    High

    CVE-2018-20135

    Last Modified: 21 Nov 2024

    Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the-middle attack. An attacker may trick Galaxy Apps into using an arbitrary hostname for which the attacker can provide a valid SSL certificate, and emulate the API of the app store to modify existing apps at installation time. The specific flaw involves an HTTP method to obtain the load-balanced hostname that enforces SSL only after obtaining a hostname from the load balancer, and a missing app signature validation in the application XML. An attacker can exploit this vulnerability to achieve Remote Code Execution on the device. The Samsung ID is SVE-2018-12071.

    Published: 7 Jun 2019
    5.3
    Medium

    CVE-2018-20523

    Last Modified: 21 Nov 2024

    Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.

    Published: 7 Jun 2019
    5.9
    Medium

    CVE-2018-5264

    Last Modified: 21 Nov 2024

    Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow remote attackers to bypass intended restrictions on "free time" Wi-Fi usage by sending a /guest/s/default/ request to obtain a cookie, and then using this cookie in a /guest/s/default/login request with the byfree parameter.

    Published: 7 Jun 2019
    7.8
    High

    CVE-2019-12777

    Last Modified: 21 Nov 2024

    An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all users. By default, /usr/local and all of its subdirectories should have permissions set to only allow non-privileged users to read and execute from the tree structure, and to deny users from creating or editing files in this location. The ENTTEC firmware startup script permits all users to read, write, and execute (rwxrwxrwx) from the /usr, /usr/local, /usr/local/dmxis, and /usr/local/bin/ directories.

    Published: 7 Jun 2019
    9.8
    Critical

    CVE-2019-12776

    Last Modified: 21 Nov 2024

    An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's authorized_keys file, enabling anyone with the associated private key to gain remote root access to all affected products.

    Published: 7 Jun 2019
    8.8
    High

    CVE-2019-12775

    Last Modified: 21 Nov 2024

    An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is granted full access to run any system commands with elevated privilege, without the need for password authentication. Should vulnerabilities be identified and exploited within the web application, it may be possible for a threat actor to create or run high-privileged binaries or executables that are available within the operating system of the device.)

    Published: 7 Jun 2019
    6.1
    Medium

    CVE-2019-12774

    Last Modified: 21 Nov 2024

    A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to the Profile Editor.

    Published: 7 Jun 2019
    7.2
    High

    CVE-2018-5265

    Last Modified: 21 Nov 2024

    Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remote attackers to execute arbitrary code with admin credentials, because /opt/vyatta/share/vyatta-cfg/templates/system/static-host-mapping/host-name/node.def does not sanitize the 'alias' or 'ips' parameter for shell metacharacters.

    Published: 7 Jun 2019
    6.1
    Medium

    CVE-2018-5798

    Last Modified: 21 Nov 2024

    This CVE relates to an unspecified cross site scripting vulnerability in Cloudera Manager.

    Published: 7 Jun 2019
    4.9
    Medium

    CVE-2018-6185

    Last Modified: 21 Nov 2024

    In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KMS: purge and undelete. The KMS ACL values for these commands are keytrustee.kms.acl.PURGE and keytrustee.kms.acl.UNDELETE respectively. The default value for the ACLs in Key Trustee KMS 5.12.0 and 5.13.0 is "*" which allows anyone with knowledge of the name of an encryption zone key and network access to the Key Trustee KMS to make those calls against known encryption zone keys. This can result in the recovery of a previously deleted, but not purged, key (undelete) or the deletion of a key in active use (purge) resulting in loss of access to encrypted HDFS data.

    Published: 7 Jun 2019
    5.5
    Medium

    CVE-2019-12477

    Last Modified: 21 Nov 2024

    Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcast fake video without any authentication via a /remote/media_control?action=setUri&uri= URI.

    Published: 7 Jun 2019
    5.4
    Medium

    CVE-2019-4070

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157015.

    Published: 7 Jun 2019
    8.8
    High

    CVE-2019-4069

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014.

    Published: 7 Jun 2019
    7.5
    High

    CVE-2019-4068

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013.

    Published: 7 Jun 2019
    7.5
    High

    CVE-2019-4067

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.

    Published: 7 Jun 2019
    8.8
    High

    CVE-2019-4066

    Last Modified: 21 Nov 2024

    IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 could allow an authenciated user to create arbitrary users which could cause ID management issues and result in code execution. IBM X-Force ID: 157011.

    Published: 7 Jun 2019
    5.3
    Medium

    CVE-2019-8282

    Last Modified: 21 Nov 2024

    Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one.

    Published: 7 Jun 2019
    6.5
    Medium

    CVE-2019-8283

    Last Modified: 21 Nov 2024

    Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it.

    Published: 7 Jun 2019
    7.8
    High

    CVE-2019-6532

    Last Modified: 21 Nov 2024

    Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user triggering incompatible type errors because the resource does not have expected properties. This may lead to remote code execution.

    Published: 7 Jun 2019
    7.8
    High

    CVE-2019-6530

    Last Modified: 21 Nov 2024

    Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer overflows, which may lead to remote code execution.

    Published: 7 Jun 2019
    9.8
    Critical

    CVE-2019-12771

    Last Modified: 21 Nov 2024

    Command injection is possible in ThinStation through 6.1.1 via shell metacharacters after the cgi-bin/CdControl.cgi action= substring, or after the cgi-bin/VolControl.cgi OK= substring.

    Published: 7 Jun 2019
    7.5
    High

    CVE-2019-12763

    Last Modified: 21 Nov 2024

    The Security Camera CZ application through 1.6.8 for Android stores potentially sensitive recorded video in external data storage, which is readable by any application.

    Published: 7 Jun 2019
    2.3
    Low

    CVE-2019-10165

    Last Modified: 21 Nov 2024

    OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.

    Published: 7 Jun 2019
    4.3
    Medium

    CVE-2019-4257

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive information in an error message may be used to conduct further attacks against the system. IBM X-Force ID: 159945.

    Published: 6 Jun 2019
    5.3
    Medium

    CVE-2019-4219

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228.

    Published: 6 Jun 2019
    3.3
    Low

    CVE-2019-4218

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 159227.

    Published: 6 Jun 2019
    6.1
    Medium

    CVE-2019-4217

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159226.

    Published: 6 Jun 2019
    7.5
    High

    CVE-2019-4162

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.

    Published: 6 Jun 2019
    3.3
    Low

    CVE-2019-4161

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 158660.

    Published: 6 Jun 2019
    4.3
    Medium

    CVE-2019-10159

    Last Modified: 21 Nov 2024

    cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.

    Published: 6 Jun 2019
    4.2
    Medium

    CVE-2019-12762

    Last Modified: 21 Nov 2024

    Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.

    Published: 6 Jun 2019
    9.8
    Critical

    CVE-2019-11523

    Last Modified: 21 Nov 2024

    Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

    Published: 6 Jun 2019
    6.5
    Medium

    CVE-2019-12492

    Last Modified: 21 Nov 2024

    Gallagher Command Centre before 7.80.939, 7.90.x before 7.90.961, and 8.x before 8.00.1128 allows arbitrary event creation and information disclosure via the FT Command Centre Service and FT Controller Service services.

    Published: 6 Jun 2019
    6.1
    Medium

    CVE-2019-3790

    Last Modified: 21 Nov 2024

    The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.

    Published: 6 Jun 2019
    9.1
    Critical

    CVE-2019-3723

    Last Modified: 21 Nov 2024

    Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter tampering vulnerability. A remote unauthenticated attacker could potentially manipulate parameters of web requests to OMSA to create arbitrary files with empty content or delete the contents of any existing file, due to improper input parameter validation

    Published: 6 Jun 2019
    7.5
    High

    CVE-2019-3722

    Last Modified: 21 Nov 2024

    Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to read arbitrary server system files by supplying specially crafted document type definitions (DTDs) in an XML request.

    Published: 6 Jun 2019
    8.8
    High

    CVE-2019-5525

    Last Modified: 21 Nov 2024

    VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture (ALSA) backend. A malicious user with normal user privileges on the guest machine may exploit this issue in conjunction with other issues to execute code on the Linux host where Workstation is installed.

    Published: 6 Jun 2019
    7.1
    High

    CVE-2019-5522

    Last Modified: 21 Nov 2024

    VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines. This issue is present in versions 10.2.x and 10.3.x prior to 10.3.10. A local attacker with non-administrative access to a Windows guest with VMware Tools installed may be able to leak kernel information or create a denial of service attack on the same Windows guest machine.

    Published: 6 Jun 2019
    3.3
    Low

    CVE-2019-12760

    Last Modified: 21 Nov 2024

    A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration.

    Published: 6 Jun 2019
    6.1
    Medium

    CVE-2018-8047

    Last Modified: 21 Nov 2024

    vtiger CRM 7.0.1 is affected by one reflected Cross-Site Scripting (XSS) vulnerability affecting version 7.0.1 and probably prior versions. This vulnerability could allow remote unauthenticated attackers to inject arbitrary web script or HTML via index.php?module=Contacts&view=List (app parameter).

    Published: 6 Jun 2019
    6.5
    Medium

    CVE-2018-9839

    Last Modified: 21 Nov 2024

    An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any user with REPORTER access or above is able to view any private issue's details (summary, description, steps to reproduce, additional information) when cloning it. By checking the 'Copy issue notes' and 'Copy attachments' checkboxes and completing the clone operation, this data also becomes public (except private notes).

    Published: 6 Jun 2019