CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-11471

    Last Modified: 21 Nov 2024

    libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context.cc mishandles references to non-existing alpha images.

    Published: 23 Apr 2019
    5.5
    Medium

    CVE-2018-20820

    Last Modified: 21 Nov 2024

    read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.

    Published: 23 Apr 2019
    7.8
    High

    CVE-2018-20819

    Last Modified: 21 Nov 2024

    io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be (incorrectly) larger than the maximum file size.

    Published: 23 Apr 2019
    7.7
    High

    CVE-2018-17169

    Last Modified: 21 Nov 2024

    An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Published: 23 Apr 2019
    9.8
    Critical

    CVE-2019-11469

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

    Published: 23 Apr 2019
    6.3
    Medium

    CVE-2019-2692

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).

    Published: 23 Apr 2019
    6.5
    Medium

    CVE-2019-5805

    Last Modified: 21 Nov 2024

    Use-after-free in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5808

    Last Modified: 21 Nov 2024

    Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5809

    Last Modified: 21 Nov 2024

    Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5811

    Last Modified: 21 Nov 2024

    Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published: 23 Apr 2019
    6.5
    Medium

    CVE-2019-5814

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5816

    Last Modified: 21 Nov 2024

    Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.

    Published: 23 Apr 2019
    7.8
    High

    CVE-2019-5819

    Last Modified: 21 Nov 2024

    Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5820

    Last Modified: 21 Nov 2024

    Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 23 Apr 2019
    6.5
    Medium

    CVE-2020-6503

    Last Modified: 21 Nov 2024

    Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5807

    Last Modified: 21 Nov 2024

    Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5813

    Last Modified: 21 Nov 2024

    Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Apr 2019
    3.3
    Low

    CVE-2019-2708

    Last Modified: 21 Nov 2024

    Vulnerability in the Data Store component of Oracle Berkeley DB. Supported versions that are affected are Prior to 6.138, prior to 6.2.38 and prior to 18.1.32. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Data Store executes to compromise Data Store. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Data Store. CVSS 3.0 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5806

    Last Modified: 21 Nov 2024

    Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Apr 2019
    6.5
    Medium

    CVE-2019-5810

    Last Modified: 21 Nov 2024

    Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 23 Apr 2019
    6.5
    Medium

    CVE-2019-5812

    Last Modified: 21 Nov 2024

    Inadequate security UI in iOS UI in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 23 Apr 2019
    7.5
    High

    CVE-2019-5815

    Last Modified: 21 Nov 2024

    Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5817

    Last Modified: 21 Nov 2024

    Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 23 Apr 2019
    6.5
    Medium

    CVE-2019-5818

    Last Modified: 21 Nov 2024

    Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5821

    Last Modified: 21 Nov 2024

    Integer overflow in PDFium in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 23 Apr 2019
    8.8
    High

    CVE-2019-5822

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published: 23 Apr 2019
    5.4
    Medium

    CVE-2019-5823

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 23 Apr 2019
    3.3
    Low

    CVE-2020-18974

    Last Modified: 21 Nov 2024

    Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.

    Published: 23 Apr 2019
    4.3
    Medium

    CVE-2020-6504

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.

    Published: 23 Apr 2019
    7.4
    High

    CVE-2019-0223

    Last Modified: 21 Nov 2024

    While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.

    Published: 23 Apr 2019
    7.8
    High

    CVE-2019-8452

    Last Modified: 21 Nov 2024

    A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

    Published: 22 Apr 2019
    6.1
    Medium

    CVE-2019-0218

    Last Modified: 21 Nov 2024

    A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail interface.

    Published: 22 Apr 2019
    9.8
    Critical

    CVE-2019-11383

    Last Modified: 21 Nov 2024

    An issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/password of a valid user via /data/data/com.medhaapps.wififtpserver/shared_prefs/com.medhaapps.wififtpserver_preferences.xml

    Published: 22 Apr 2019
    9.8
    Critical

    CVE-2019-11384

    Last Modified: 21 Nov 2024

    The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), which allows a non-root user to find out the username/password of a valid user via /data/data/com.zalora.android/shared_prefs/login_data.xml.

    Published: 22 Apr 2019
    —
    Unknown

    CVE-2019-5428

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11358. Reason: This candidate is a duplicate of CVE-2019-11358. Notes: All CVE users should reference CVE-2019-11358 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Apr 2019
    8.1
    High

    CVE-2019-10248

    Last Modified: 21 Nov 2024

    Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.

    Published: 22 Apr 2019
    6.1
    Medium

    CVE-2019-9955

    Last Modified: 21 Nov 2024

    On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

    Published: 22 Apr 2019
    7.1
    High

    CVE-2016-1587

    Last Modified: 21 Nov 2024

    The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

    Published: 22 Apr 2019
    1.8
    Low

    CVE-2016-1586

    Last Modified: 21 Nov 2024

    A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

    Published: 22 Apr 2019
    9.8
    Critical

    CVE-2016-1585

    Last Modified: 2 May 2025

    In all versions of AppArmor mount rules are accidentally widened when compiled.

    Published: 22 Apr 2019
    1.6
    Low

    CVE-2016-1584

    Last Modified: 21 Nov 2024

    In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.

    Published: 22 Apr 2019
    6.7
    Medium

    CVE-2016-1579

    Last Modified: 21 Nov 2024

    UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run arbitrary commands in an unconfined environment as the phablet user.

    Published: 22 Apr 2019
    7.8
    High

    CVE-2016-1573

    Last Modified: 21 Nov 2024

    Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.

    Published: 22 Apr 2019
    2
    Low

    CVE-2015-1343

    Last Modified: 21 Nov 2024

    All versions of unity-scope-gdrive logs search terms to syslog.

    Published: 22 Apr 2019
    7.4
    High

    CVE-2015-1341

    Last Modified: 21 Nov 2024

    Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.

    Published: 22 Apr 2019
    7
    High

    CVE-2015-1340

    Last Modified: 21 Nov 2024

    LXD before version 0.19-0ubuntu5 doUidshiftIntoContainer() has an unsafe Chmod() call that races against the stat in the Filepath.Walk() function. A symbolic link created in that window could cause any file on the system to have any mode of the attacker's choice.

    Published: 22 Apr 2019
    3.9
    Low

    CVE-2015-1327

    Last Modified: 21 Nov 2024

    Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using the DBUS API to export file:///etc/passwd which would then send a copy of that file to another app.

    Published: 22 Apr 2019
    5.7
    Medium

    CVE-2015-1326

    Last Modified: 21 Nov 2024

    python-dbusmock before version 0.15.1 AddTemplate() D-Bus method call or DBusTestCase.spawn_server_template() method could be tricked into executing malicious code if an attacker supplies a .pyc file.

    Published: 22 Apr 2019
    5.5
    Medium

    CVE-2015-1320

    Last Modified: 21 Nov 2024

    The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu MAAS versions prior to 1.9.2.

    Published: 22 Apr 2019
    6.4
    Medium

    CVE-2015-1316

    Last Modified: 21 Nov 2024

    Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.

    Published: 22 Apr 2019