CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2020-19190

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

    Published: 3 May 2019
    6.5
    Medium

    CVE-2020-19186

    Last Modified: 27 Nov 2024

    Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

    Published: 3 May 2019
    7.8
    High

    CVE-2019-11687

    Last Modified: 2 Jun 2026

    An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable headers for multiple operating systems, including Portable Executable (PE) files for Windows and Executable and Linkable Format (ELF) files for Linux-based systems. This space is left unspecified so that dual-purpose files can be created. For example, dual-purpose TIFF/DICOM files are used in digital whole slide imaging applications in medicine. This design flaw enables system-wide compromise as malicious DICOM files are routinely shared between medical devices and hospital systems and transported via removable media for patient care coordination. To exploit this vulnerability, someone must execute the maliciously crafted file. These files can be executable even with the .dcm file extension. Anti-malware configurations at healthcare facilities often ignore medical imagery. DICOM files exist on systems that process protected health information, and successful exploitation could result in violations of regulatory compliance requirements such as HIPAA and FDA postmarket obligations.

    Published: 2 May 2019
    7.5
    High

    CVE-2019-9826

    Last Modified: 21 Nov 2024

    The fulltext search component in phpBB before 3.2.6 allows Denial of Service.

    Published: 2 May 2019
    6.1
    Medium

    CVE-2018-10383

    Last Modified: 21 Nov 2024

    Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2018-16988

    Last Modified: 8 Jun 2026

    An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.

    Published: 2 May 2019
    7.5
    High

    CVE-2018-16961

    Last Modified: 21 Nov 2024

    An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the file parameter, allowing remote attackers to read PDF files in arbitrary directories.

    Published: 2 May 2019
    6.1
    Medium

    CVE-2018-16960

    Last Modified: 21 Nov 2024

    An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter.

    Published: 2 May 2019
    6.1
    Medium

    CVE-2018-16718

    Last Modified: 21 Nov 2024

    An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2018-16717

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.

    Published: 2 May 2019
    9.1
    Critical

    CVE-2018-16716

    Last Modified: 21 Nov 2024

    A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

    Published: 2 May 2019
    7.5
    High

    CVE-2019-9017

    Last Modified: 21 Nov 2024

    DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.

    Published: 2 May 2019
    6.1
    Medium

    CVE-2019-3490

    Last Modified: 21 Nov 2024

    A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older versions may be affected but were not tested as they are out of support.

    Published: 2 May 2019
    8.8
    High

    CVE-2017-18374

    Last Modified: 21 Nov 2024

    The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has two user accounts with default passwords, including a hardcoded service account with the username true and password true. These accounts can be used to login to the web interface, exploit authenticated command injections and change router settings for malicious purposes.

    Published: 2 May 2019
    8.8
    High

    CVE-2017-18373

    Last Modified: 21 Nov 2024

    The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username user3 and and a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.

    Published: 2 May 2019
    8.8
    High

    CVE-2017-18372

    Last Modified: 21 Nov 2024

    The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerability in the Time Setting function, which is only accessible by an authenticated user. The vulnerability is in the tools_time.asp page and can be exploited through the uiViewSNTPServer parameter. Authentication can be achieved by exploiting CVE-2017-18373.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2017-18371

    Last Modified: 21 Nov 2024

    The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234. These accounts can be used to login to the web interface, exploit authenticated command injections, and change router settings for malicious purposes.

    Published: 2 May 2019
    8.8
    High

    CVE-2017-18370

    Last Modified: 21 Nov 2024

    The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is only accessible by an authenticated user. The vulnerability is in the logSet.asp page and can be exploited through the ServerIP parameter. Authentication can be achieved by exploiting CVE-2017-18371.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2017-18369

    Last Modified: 21 Nov 2024

    The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2017-18368

    Last Modified: 5 Nov 2025

    The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.

    Published: 2 May 2019
    6.4
    Medium

    CVE-2018-2015

    Last Modified: 21 Nov 2024

    IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 155195.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2019-11682

    Last Modified: 21 Nov 2024

    A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP command, a related issue to CVE-2019-11395.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2019-11678

    Last Modified: 21 Nov 2024

    The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

    Published: 2 May 2019
    9.8
    Critical

    CVE-2019-11677

    Last Modified: 21 Nov 2024

    The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.

    Published: 2 May 2019
    6.1
    Medium

    CVE-2019-11676

    Last Modified: 21 Nov 2024

    The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

    Published: 2 May 2019
    7
    High

    CVE-2019-11675

    Last Modified: 21 Nov 2024

    The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to /etc/bash_completion.d. NOTE: this is an issue in the Debian packaging of the Groonga HTTP server.

    Published: 2 May 2019
    7.8
    High

    CVE-2019-3839

    Last Modified: 21 Nov 2024

    It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

    Published: 2 May 2019
    9.1
    Critical

    CVE-2019-11036

    Last Modified: 21 Nov 2024

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

    Published: 2 May 2019
    6.1
    Medium

    CVE-2018-8035

    Last Modified: 21 Nov 2024

    This vulnerability relates to the user's browser processing of DUCC webpage input data.The javascript comprising Apache UIMA DUCC (<= 2.2.2) which runs in the user's browser does not sufficiently filter user supplied inputs, which may result in unintended execution of user supplied javascript code.

    Published: 1 May 2019
    9.8
    Critical

    CVE-2019-10952

    Last Modified: 20 Feb 2026

    An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.

    Published: 1 May 2019
    7.5
    High

    CVE-2019-10954

    Last Modified: 20 Feb 2026

    An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major non-recoverable faulted state (MNRF) in CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.

    Published: 1 May 2019
    5.4
    Medium

    CVE-2019-6562

    Last Modified: 21 Nov 2024

    In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    Published: 1 May 2019
    7.5
    High

    CVE-2019-11641

    Last Modified: 21 Nov 2024

    Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal variation in size within HTML templates, giving attackers the ability to detect and avoid this system.

    Published: 1 May 2019
    —
    Unknown

    CVE-2019-3791

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 May 2019
    —
    Unknown

    CVE-2018-17606

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16620. Reason: This candidate is a reservation duplicate of CVE-2018-16620. Notes: All CVE users should reference CVE-2018-16620 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 May 2019
    8.8
    High

    CVE-2019-11640

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.

    Published: 1 May 2019
    8.8
    High

    CVE-2019-11639

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.

    Published: 1 May 2019
    6.5
    Medium

    CVE-2019-11638

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.

    Published: 1 May 2019
    6.5
    Medium

    CVE-2019-11637

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.

    Published: 1 May 2019
    7.5
    High

    CVE-2019-11636

    Last Modified: 21 Nov 2024

    Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.

    Published: 1 May 2019
    5.4
    Medium

    CVE-2019-4258

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 159946.

    Published: 1 May 2019
    5.4
    Medium

    CVE-2018-1933

    Last Modified: 21 Nov 2024

    IBM Planning Analytics 2.0 through 2.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153177.

    Published: 1 May 2019
    5.9
    Medium

    CVE-2018-1608

    Last Modified: 21 Nov 2024

    IBM Rational Engineering Lifecycle Manager 6.0 through 6.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 143798.

    Published: 1 May 2019
    7.5
    High

    CVE-2019-11633

    Last Modified: 21 Nov 2024

    HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylmao.wpengine.com hostnames within the fake WordPress templates. This allows attackers to discover and avoid this honeypot system.

    Published: 1 May 2019
    8.1
    High

    CVE-2019-11632

    Last Modified: 21 Nov 2024

    In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscoped permission scoped to a specific project could view or edit unscoped variables from a different project. (These permissions are only used in custom User Roles and do not affect built in User Roles.)

    Published: 1 May 2019
    —
    Unknown

    CVE-2019-11631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 May 2019
    8.2
    High

    CVE-2019-11628

    Last Modified: 21 Nov 2024

    An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3, June 2018 Patch 3, September 2018 Patch 4, November 2018 Patch 4, or February 2019 Patch 2. An authenticated user may be able to bypass intended file-read restrictions via crafted Browser requests.

    Published: 1 May 2019
    7.8
    High

    CVE-2019-2054

    Last Modified: 21 Nov 2024

    In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499

    Published: 1 May 2019
    9.8
    Critical

    CVE-2019-11683

    Last Modified: 21 Nov 2024

    udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling of padded packets, aka the "GRO packet of death" issue.

    Published: 1 May 2019
    7
    High

    CVE-2019-10143

    Last Modified: 21 Nov 2024

    It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."

    Published: 1 May 2019