CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-0231

    Last Modified: 13 Feb 2025

    Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.

    Published: 14 Apr 2019
    5.9
    Medium

    CVE-2019-11323

    Last Modified: 21 Nov 2024

    HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.

    Published: 14 Apr 2019
    6.5
    Medium

    CVE-2019-11472

    Last Modified: 21 Nov 2024

    ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a denial-of-service (divide-by-zero error) by crafting an XWD image file in which the header indicates neither LSB first nor MSB first.

    Published: 14 Apr 2019
    8.8
    High

    CVE-2019-11229

    Last Modified: 21 Nov 2024

    models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

    Published: 13 Apr 2019
    7.5
    High

    CVE-2019-11228

    Last Modified: 21 Nov 2024

    repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.

    Published: 13 Apr 2019
    5.5
    Medium

    CVE-2018-20509

    Last Modified: 21 Nov 2024

    The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading " ref *desc *node" lines in a debugfs file.

    Published: 13 Apr 2019
    5.5
    Medium

    CVE-2019-11459

    Last Modified: 21 Nov 2024

    The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

    Published: 13 Apr 2019
    7.8
    High

    CVE-2019-11461

    Last Modified: 21 Nov 2024

    An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

    Published: 13 Apr 2019
    6.1
    Medium

    CVE-2019-0221

    Last Modified: 21 Nov 2024

    The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

    Published: 13 Apr 2019
    9
    Critical

    CVE-2019-11460

    Last Modified: 21 Nov 2024

    An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.

    Published: 13 Apr 2019
    8.8
    High

    CVE-2017-18366

    Last Modified: 21 Nov 2024

    Subrion CMS 4.1.5 has CSRF in blog/delete/.

    Published: 12 Apr 2019
    9.8
    Critical

    CVE-2019-6526

    Last Modified: 21 Nov 2024

    Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacker to capture sensitive data such as an administrative password.

    Published: 12 Apr 2019
    7.8
    High

    CVE-2019-11222

    Last Modified: 21 Nov 2024

    gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

    Published: 12 Apr 2019
    7.8
    High

    CVE-2019-11221

    Last Modified: 21 Nov 2024

    GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

    Published: 12 Apr 2019
    6.1
    Medium

    CVE-2018-16259

    Last Modified: 21 Nov 2024

    There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-settings large_feed_limit. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

    Published: 12 Apr 2019
    6.1
    Medium

    CVE-2018-16258

    Last Modified: 21 Nov 2024

    There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via pmxi-admin-import custom_type. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

    Published: 12 Apr 2019
    6.1
    Medium

    CVE-2018-16257

    Last Modified: 21 Nov 2024

    There are multiple XSS vulnerabilities in WP All Import plugin 3.4.9 for WordPress via action=template. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

    Published: 12 Apr 2019
    6.1
    Medium

    CVE-2018-16256

    Last Modified: 21 Nov 2024

    There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via Add Filtering Options(Add Rule). NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

    Published: 12 Apr 2019
    6.1
    Medium

    CVE-2018-16255

    Last Modified: 21 Nov 2024

    There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=evaluate. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

    Published: 12 Apr 2019
    6.1
    Medium

    CVE-2018-16254

    Last Modified: 21 Nov 2024

    There is an XSS vulnerability in WP All Import plugin 3.4.9 for WordPress via action=options. NOTE: The vendor states that this is not a vulnerability. WP All Import is only able to be used by a logged in administrator, and the action described can only be taken advantage of by a logged in administrator

    Published: 12 Apr 2019
    4.8
    Medium

    CVE-2018-13137

    Last Modified: 21 Nov 2024

    The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.

    Published: 12 Apr 2019
    9.8
    Critical

    CVE-2019-10880

    Last Modified: 21 Nov 2024

    Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

    Published: 12 Apr 2019
    5.4
    Medium

    CVE-2019-1574

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.

    Published: 12 Apr 2019
    7.8
    High

    CVE-2018-6269

    Last Modified: 21 Nov 2024

    NVIDIA Jetson TX2 contains a vulnerability in the kernel driver where input/output control (IOCTL) handling for user mode requests could create a non-trusted pointer dereference, which may lead to information disclosure, denial of service, escalation of privileges, or code execution. The updates apply to all versions prior to R28.3.

    Published: 12 Apr 2019
    5.5
    Medium

    CVE-2018-6239

    Last Modified: 21 Nov 2024

    NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may access the contents of cached information in an unauthorized manner, which may lead to information disclosure. The updates apply to all versions prior to R28.3.

    Published: 12 Apr 2019
    9.8
    Critical

    CVE-2017-14199

    Last Modified: 21 Nov 2024

    A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0.

    Published: 12 Apr 2019
    8.1
    High

    CVE-2019-11213

    Last Modified: 21 Nov 2024

    In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse Desktop Client 5.x before Secure Desktop 5.3R7 and Pulse Desktop Client 9.x before Secure Desktop 9.0R3. It also affects (for Network Connect customers) Pulse Connect Secure 8.1 before 8.1R14, 8.3 before 8.3R7, and 9.0 before 9.0R3.

    Published: 12 Apr 2019
    9.8
    Critical

    CVE-2019-11196

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).

    Published: 12 Apr 2019
    5.5
    Medium

    CVE-2019-19555

    Last Modified: 21 Nov 2024

    read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.

    Published: 12 Apr 2019
    7.5
    High

    CVE-2019-3883

    Last Modified: 21 Nov 2024

    In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could repeatedly create hanging LDAP requests to hang all the workers, resulting in a Denial of Service.

    Published: 12 Apr 2019
    9.8
    Critical

    CVE-2019-0228

    Last Modified: 21 Nov 2024

    Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

    Published: 12 Apr 2019
    7.8
    High

    CVE-2019-6534

    Last Modified: 21 Nov 2024

    The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an attacker to load and execute a malicious file.

    Published: 11 Apr 2019
    8.8
    High

    CVE-2019-6525

    Last Modified: 21 Nov 2024

    AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.

    Published: 11 Apr 2019
    8.8
    High

    CVE-2018-20487

    Last Modified: 21 Nov 2024

    An issue was discovered in the firewall3 component in Inteno IOPSYS 1.0 through 3.16. The attacker must make a JSON-RPC method call to add a firewall rule as an "include" and point the "path" argument to a malicious script or binary. This gets executed as root when the firewall changes are committed.

    Published: 11 Apr 2019
    6.1
    Medium

    CVE-2018-19202

    Last Modified: 21 Nov 2024

    A reflected XSS vulnerability in index.php in MyBB 1.8.x through 1.8.19 allows remote attackers to inject JavaScript via the 'upsetting[bburl]' parameter.

    Published: 11 Apr 2019
    6.1
    Medium

    CVE-2019-6796

    Last Modified: 21 Nov 2024

    An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows XSS (issue 2 of 2). The user status field contains a lack of input validation and output encoding that results in a persistent XSS.

    Published: 11 Apr 2019
    9.8
    Critical

    CVE-2019-7644

    Last Modified: 21 Nov 2024

    Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.

    Published: 11 Apr 2019
    5.5
    Medium

    CVE-2019-6493

    Last Modified: 21 Nov 2024

    SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user defined bytes and size when IOCTL 0x9C401CC0 is called. This kernel pointer can be leaked if the kernel pool becomes a "big" pool.

    Published: 11 Apr 2019
    8.8
    High

    CVE-2019-9056

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate.php or class.FrontEndUsersManipulator.php), it is possible to reach an unserialize call with an untrusted __FEU__ cookie, and achieve authenticated object injection.

    Published: 11 Apr 2019
    9.8
    Critical

    CVE-2019-9733

    Last Modified: 21 Nov 2024

    An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory.

    Published: 11 Apr 2019
    6.1
    Medium

    CVE-2019-7219

    Last Modified: 21 Nov 2024

    Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a discontinued product. The issue was fixed in later Zarafa Webapp versions; however, some former Zarafa Webapp customers use the related Kopano product instead.

    Published: 11 Apr 2019
    9.8
    Critical

    CVE-2019-5715

    Last Modified: 21 Nov 2024

    All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4, and 4.3.1 allows Reflected SQL Injection through Form and DataObject.

    Published: 11 Apr 2019
    8.8
    High

    CVE-2019-9976

    Last Modified: 21 Nov 2024

    The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.

    Published: 11 Apr 2019
    7.5
    High

    CVE-2019-9975

    Last Modified: 21 Nov 2024

    DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.

    Published: 11 Apr 2019
    9.1
    Critical

    CVE-2019-9974

    Last Modified: 21 Nov 2024

    diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.

    Published: 11 Apr 2019
    7.6
    High

    CVE-2019-5024

    Last Modified: 21 Nov 2024

    A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment, resulting in full administrator access to the underlying operating system. An attacker can connect to the device via USB port with a keyboard or other HID device to trigger this vulnerability.

    Published: 11 Apr 2019
    8.6
    High

    CVE-2019-6610

    Last Modified: 21 Nov 2024

    On BIG-IP versions 14.0.0-14.0.0.4, 13.0.0-13.1.1.1, 12.1.0-12.1.4, 11.6.0-11.6.3.4, and 11.5.1-11.5.8, the system is vulnerable to a denial of service attack when performing URL classification.

    Published: 11 Apr 2019
    6.1
    Medium

    CVE-2019-5673

    Last Modified: 21 Nov 2024

    NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Memory Management Unit (SMMU) improperly checks for a fault condition, causing transactions to be discarded, which may lead to denial of service.

    Published: 11 Apr 2019
    9.1
    Critical

    CVE-2019-5672

    Last Modified: 21 Nov 2024

    NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.

    Published: 11 Apr 2019
    8.8
    High

    CVE-2018-17305

    Last Modified: 21 Nov 2024

    UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.

    Published: 11 Apr 2019