CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-3482

    Last Modified: 21 Nov 2024

    Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.

    Published: 25 Mar 2019
    7.1
    High

    CVE-2019-3481

    Last Modified: 21 Nov 2024

    Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.

    Published: 25 Mar 2019
    6.1
    Medium

    CVE-2019-3480

    Last Modified: 21 Nov 2024

    Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.

    Published: 25 Mar 2019
    9.8
    Critical

    CVE-2015-3953

    Last Modified: 21 Nov 2024

    Hard-coded accounts may be used to access Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.

    Published: 25 Mar 2019
    9.8
    Critical

    CVE-2019-3479

    Last Modified: 21 Nov 2024

    Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.

    Published: 25 Mar 2019
    8.8
    High

    CVE-2017-9362

    Last Modified: 21 Nov 2024

    ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

    Published: 25 Mar 2019
    6.5
    Medium

    CVE-2017-9376

    Last Modified: 21 Nov 2024

    ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.

    Published: 25 Mar 2019
    7.5
    High

    CVE-2015-3952

    Last Modified: 21 Nov 2024

    Wireless keys are stored in plain text on Hospira Plum A+ Infusion System version 13.4 and prior, Plum A+3 Infusion System version 13.6 and prior, and Symbiq Infusion System, version 3.13 and prior. Hospira recommends that customers close Port 20/FTP and Port 23/TELNET on the affected devices. Hospira has also released the Plum 360 Infusion System which is not vulnerable to this issue.

    Published: 25 Mar 2019
    6.1
    Medium

    CVE-2019-10016

    Last Modified: 21 Nov 2024

    GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.

    Published: 25 Mar 2019
    7.5
    High

    CVE-2019-0199

    Last Modified: 21 Nov 2024

    The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

    Published: 25 Mar 2019
    8.1
    High

    CVE-2019-3879

    Last Modified: 21 Nov 2024

    It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the calling user is skipped. A user with low privileges (eg Basic Operations) could exploit this flaw to delete disks attached to guests.

    Published: 25 Mar 2019
    9.8
    Critical

    CVE-2019-1003041

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.

    Published: 25 Mar 2019
    5.4
    Medium

    CVE-2019-1003042

    Last Modified: 21 Nov 2024

    A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.

    Published: 25 Mar 2019
    6.1
    Medium

    CVE-2019-3810

    Last Modified: 21 Nov 2024

    A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

    Published: 25 Mar 2019
    8.1
    High

    CVE-2020-18771

    Last Modified: 21 Nov 2024

    Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.

    Published: 25 Mar 2019
    6.5
    Medium

    CVE-2020-18773

    Last Modified: 21 Nov 2024

    An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

    Published: 25 Mar 2019
    6.5
    Medium

    CVE-2020-18774

    Last Modified: 21 Nov 2024

    A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.

    Published: 25 Mar 2019
    9.8
    Critical

    CVE-2019-1003040

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.

    Published: 25 Mar 2019
    4.8
    Medium

    CVE-2019-10027

    Last Modified: 21 Nov 2024

    PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10026

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the psOpRoll case.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10025

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10024

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Bresenham parameters.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10023

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10022

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx.cc.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10021

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10020

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10019

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes.

    Published: 24 Mar 2019
    5.5
    Medium

    CVE-2019-10018

    Last Modified: 21 Nov 2024

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.

    Published: 24 Mar 2019
    5.4
    Medium

    CVE-2019-10017

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" action to the File Picker.

    Published: 24 Mar 2019
    7.2
    High

    CVE-2019-10015

    Last Modified: 21 Nov 2024

    baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file.

    Published: 24 Mar 2019
    6.5
    Medium

    CVE-2019-10014

    Last Modified: 21 Nov 2024

    In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.

    Published: 24 Mar 2019
    6.1
    Medium

    CVE-2019-10010

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to insert unsafe links into HTML by using double-encoded HTML entities that are not properly escaped during rendering, a different vulnerability than CVE-2018-20583.

    Published: 24 Mar 2019
    6.1
    Medium

    CVE-2019-9978

    Last Modified: 7 Nov 2025

    The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.

    Published: 24 Mar 2019
    8.8
    High

    CVE-2019-9977

    Last Modified: 21 Nov 2024

    The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows attackers to trigger firmware code execution, and display a crafted message to vehicle occupants.

    Published: 24 Mar 2019
    6.5
    Medium

    CVE-2019-9970

    Last Modified: 21 Nov 2024

    Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9969

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x385399.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9968

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlQueueWorkItem.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9967

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlPrefixUnicodeString.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9966

    Last Modified: 21 Nov 2024

    XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9965

    Last Modified: 21 Nov 2024

    XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlReAllocateHeap.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9964

    Last Modified: 21 Nov 2024

    XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlpNtMakeTemporaryKey.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9963

    Last Modified: 21 Nov 2024

    XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to ntdll!RtlFreeHeap.

    Published: 24 Mar 2019
    7.8
    High

    CVE-2019-9962

    Last Modified: 21 Nov 2024

    XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to VCRUNTIME140!memcpy.

    Published: 24 Mar 2019
    9.8
    Critical

    CVE-2019-9960

    Last Modified: 21 Nov 2024

    The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.

    Published: 24 Mar 2019
    8.8
    High

    CVE-2015-3965

    Last Modified: 21 Nov 2024

    Hospira Symbiq Infusion System 3.13 and earlier allows remote authenticated users to trigger "unanticipated operations" by leveraging "elevated privileges" for an unspecified call to an incorrectly exposed function.

    Published: 23 Mar 2019
    9.8
    Critical

    CVE-2019-9945

    Last Modified: 21 Nov 2024

    SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verify the status of a user cookie. If not set, a user is redirected to the login page. An arbitrary value can be provided for this cookie to access the web interface without valid user credentials. If customers have not followed SoftNAS deployment best practices and expose SoftNAS StorageCenter ports directly to the internet, this vulnerability allows an attacker to gain access to the Webadmin interface to create new users or execute arbitrary commands with administrative privileges, compromising both the platform and the data.

    Published: 23 Mar 2019
    3.7
    Low

    CVE-2019-9942

    Last Modified: 21 Nov 2024

    A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place.

    Published: 23 Mar 2019
    7.8
    High

    CVE-2019-0204

    Last Modified: 21 Nov 2024

    A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.

    Published: 23 Mar 2019
    6.1
    Medium

    CVE-2019-9947

    Last Modified: 21 Nov 2024

    An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

    Published: 23 Mar 2019
    9.1
    Critical

    CVE-2019-9948

    Last Modified: 21 Nov 2024

    urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

    Published: 23 Mar 2019