CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-4039

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local attacker to cause a denial of service within the error log reporting system. IBM X-Force ID: 156163.

    Published: 23 May 2019
    5.5
    Medium

    CVE-2019-12298

    Last Modified: 21 Nov 2024

    Leanify 0.4.3 allows remote attackers to trigger an out-of-bounds write (1024 bytes) via a modified input file.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-12042

    Last Modified: 21 Nov 2024

    Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.

    Published: 23 May 2019
    7.5
    High

    CVE-2019-10977

    Last Modified: 21 Nov 2024

    In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and cause a denial-of-service condition.

    Published: 23 May 2019
    8.8
    High

    CVE-2019-9949

    Last Modified: 21 Nov 2024

    Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks. Specifically, this occurs by uploading a tar archive that contains a symbolic link, then uploading another archive that writes a file to the link using the "cgi_untar" command. Other commands might also be susceptible. Code can be executed because the "name" parameter passed to the cgi_unzip command is not sanitized.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-12297

    Last Modified: 21 Nov 2024

    An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-11873

    Last Modified: 21 Nov 2024

    wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker sends a crafted hello client packet over the network to a TLSv1.3 wolfSSL server. The length fields of the packet: record length, client hello length, total extensions length, PSK extension length, total identity length, and identity length contain their maximum value which is 2^16. The identity data field of the PSK extension of the packet contains the attack data, to be stored in the undefined memory (RAM) of the server. The size of the data is about 65 kB. Possibly the attacker can perform a remote code execution attack.

    Published: 23 May 2019
    7.5
    High

    CVE-2018-15664

    Last Modified: 21 Nov 2024

    In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-12450

    Last Modified: 21 Nov 2024

    file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

    Published: 23 May 2019
    9.8
    Critical

    CVE-2019-10158

    Last Modified: 13 Feb 2025

    A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

    Published: 23 May 2019
    8.8
    High

    CVE-2019-12293

    Last Modified: 21 Nov 2024

    In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths.

    Published: 23 May 2019
    5.9
    Medium

    CVE-2018-7803

    Last Modified: 21 Nov 2024

    A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex TriStation Emulator V1.2.0, which could cause the emulator to crash when sending a specially crafted packet. The emulator is used infrequently for application logic testing. It is susceptible to an attack only while running in off-line mode. This vulnerability does not exist in Triconex hardware products and therefore has no effect on the operating safety functions in a plant.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7844

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-6808

    Last Modified: 21 Nov 2024

    A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a remote code execution by overwriting configuration settings of the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-6807

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible denial of service when writing sensitive application variables to the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-6806

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading variables in the controller using Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7857

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible Denial of Service when writing out of bounds variables to the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7856

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a possible denial of Service when writing invalid memory blocks to the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7855

    Last Modified: 21 Nov 2024

    A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a Denial of Service when sending invalid breakpoint parameters to the controller over Modbus

    Published: 22 May 2019
    8.8
    High

    CVE-2018-7201

    Last Modified: 21 Nov 2024

    CSV Injection was discovered in ProjectSend before r1053, affecting victims who import the data into Microsoft Excel.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7854

    Last Modified: 21 Nov 2024

    A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a denial of Service when sending invalid debug parameters to the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7853

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading invalid physical memory blocks in the controller over Modbus

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7852

    Last Modified: 29 May 2026

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7845

    Last Modified: 21 Nov 2024

    A CWE-125: Out-of-bounds Read vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.

    Published: 22 May 2019
    5.3
    Medium

    CVE-2018-7850

    Last Modified: 21 Nov 2024

    A CWE-807: Reliance on Untrusted Inputs in a Security Decision vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause invalid information displayed in Unity Pro software.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2018-7847

    Last Modified: 21 Nov 2024

    A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service or potential code execution by overwriting configuration settings of the controller over Modbus.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2018-7842

    Last Modified: 21 Nov 2024

    A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7848

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7843

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7849

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause a possible Denial of Service due to improper data integrity check when sending files the controller over Modbus.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2018-7846

    Last Modified: 21 Nov 2024

    A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2018-7851

    Last Modified: 21 Nov 2024

    CWE-119: Buffer errors vulnerability exists in Modicon M580 with firmware prior to V2.50, Modicon M340 with firmware prior to V3.01, BMxCRA312xx with firmware prior to V2.40, All firmware versions of Modicon Premium and 140CRA312xxx when sending a specially crafted Modbus packet, which could cause a denial of service to the device that would force a restart to restore availability.

    Published: 22 May 2019
    9.1
    Critical

    CVE-2019-6816

    Last Modified: 21 Nov 2024

    In Modicon Quantum all firmware versions, a CWE-94: Code Injection vulnerability could cause an unauthorized firmware modification with possible Denial of Service when using Modbus protocol.

    Published: 22 May 2019
    9.1
    Critical

    CVE-2019-6815

    Last Modified: 21 Nov 2024

    In Modicon Quantum all firmware versions, CWE-264: Permissions, Privileges, and Access Control vulnerabilities could cause a denial of service or unauthorized modifications of the PLC configuration when using Ethernet/IP protocol.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2018-7788

    Last Modified: 21 Nov 2024

    A CWE-255 Credentials Management vulnerability exists in Modicon Quantum with firmware versions prior to V2.40. which could cause a Denial Of Service when using a Telnet connection.

    Published: 22 May 2019
    6.1
    Medium

    CVE-2018-7834

    Last Modified: 21 Nov 2024

    A CWE-79 Cross-Site Scripting vulnerability exists in all versions of the TSXETG100 allowing an attacker to send a specially crafted URL with an embedded script to a user that would then be executed within the context of that user.

    Published: 22 May 2019
    7.2
    High

    CVE-2019-6812

    Last Modified: 21 Nov 2024

    A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 which could cause a confidentiality issue when using FTP protocol.

    Published: 22 May 2019
    9.8
    Critical

    CVE-2017-5863

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

    Published: 22 May 2019
    7.5
    High

    CVE-2019-6819

    Last Modified: 29 May 2026

    A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial of Service when specific Modbus frames are sent to the controller in the products: Modicon M340 - firmware versions prior to V3.01, Modicon M580 - firmware versions prior to V2.80, All firmware versions of Modicon Quantum and Modicon Premium.

    Published: 22 May 2019
    6.5
    Medium

    CVE-2019-6821

    Last Modified: 21 Nov 2024

    CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when using Ethernet communication in Modicon M580 firmware versions prior to V2.30, and all firmware versions of Modicon M340, Modicon Premium, Modicon Quantum.

    Published: 22 May 2019
    8.2
    High

    CVE-2019-6820

    Last Modified: 28 May 2026

    A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device IP configuration (IP address, network mask and gateway IP address) when a specific Ethernet frame is received in all versions of: Modicon M100, Modicon M200, Modicon M221, ATV IMC drive controller, Modicon M241, Modicon M251, Modicon M258, Modicon LMC058, Modicon LMC078, PacDrive Eco ,PacDrive Pro, PacDrive Pro2

    Published: 22 May 2019
    9.8
    Critical

    CVE-2019-6814

    Last Modified: 21 Nov 2024

    A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 which could cause impact to confidentiality, integrity, and availability when a remote attacker crafts a malicious request to the encoder webUI.

    Published: 22 May 2019
    6.1
    Medium

    CVE-2017-5864

    Last Modified: 21 Nov 2024

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

    Published: 22 May 2019
    5.3
    Medium

    CVE-2018-7823

    Last Modified: 21 Nov 2024

    A Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause remote launch of SoMachine Basic when sending crafted ethernet message.

    Published: 22 May 2019
    5.5
    Medium

    CVE-2018-7822

    Last Modified: 21 Nov 2024

    An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting SoMachine Basic.

    Published: 22 May 2019
    7.5
    High

    CVE-2018-7821

    Last Modified: 29 May 2026

    An Environment (CWE-2) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause cycle time impact when flooding the M221 ethernet interface while the Ethernet/IP adapter is activated.

    Published: 22 May 2019
    8.8
    High

    CVE-2018-7829

    Last Modified: 21 Nov 2024

    An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which allows an attacker to execute arbitrary system commands.

    Published: 22 May 2019
    8.8
    High

    CVE-2018-7828

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera when an authenticated user clicks a specially crafted malicious link while logged into the camera.

    Published: 22 May 2019
    5.4
    Medium

    CVE-2017-5871

    Last Modified: 21 Nov 2024

    Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

    Published: 22 May 2019
    5.4
    Medium

    CVE-2018-7827

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra Enhanced PTZ Camera which a remote attacker can execute arbitrary HTML and script code in a user’s browser session.

    Published: 22 May 2019