CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2019-1716

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code. The vulnerability exists because the software improperly validates user-supplied input during user authentication. An attacker could exploit this vulnerability by connecting to an affected device using HTTP and supplying malicious user credentials. A successful exploit could allow the attacker to trigger a reload of an affected device, resulting in a DoS condition, or to execute arbitrary code with the privileges of the app user. Cisco fixed this vulnerability in the following SIP Software releases: 10.3(1)SR5 and later for Cisco Unified IP Conference Phone 8831; 11.0(4)SR3 and later for Cisco Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 and later for the rest of the Cisco IP Phone 7800 Series and 8800 Series.

    Published: 22 Mar 2019
    7.5
    High

    CVE-2019-1763

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to bypass authorization, access critical services, and cause a denial of service (DoS) condition. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitting a crafted URL. A successful exploit could allow the attacker to gain unauthorized access to critical services and cause a DoS condition. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series. Cisco IP Conference Phone 8831 is not affected.

    Published: 22 Mar 2019
    8.1
    High

    CVE-2019-1764

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading an authenticated user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on a targeted device via a web browser and with the privileges of the user. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series. Cisco IP Conference Phone 8831 is not affected.

    Published: 22 Mar 2019
    8.1
    High

    CVE-2019-1765

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series.

    Published: 22 Mar 2019
    7.5
    High

    CVE-2019-1766

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An attacker who has valid administrator credentials for an affected system could exploit this vulnerability by sending a crafted, remote connection request to an affected system. A successful exploit could allow the attacker to write a file that consumes most of the available disk space on the system, causing application functions to operate abnormally and leading to a DoS condition. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 12.5(1)SR1.

    Published: 22 Mar 2019
    6.1
    Medium

    CVE-2018-20165

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.

    Published: 22 Mar 2019
    5.3
    Medium

    CVE-2019-9649

    Last Modified: 21 Nov 2024

    An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.

    Published: 22 Mar 2019
    7.5
    High

    CVE-2019-4052

    Last Modified: 21 Nov 2024

    IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered users. IBM X-Force ID: 156544.

    Published: 22 Mar 2019
    5.4
    Medium

    CVE-2019-4035

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the fake ICN website. IBM X-Force ID: 156001.

    Published: 22 Mar 2019
    5.3
    Medium

    CVE-2019-9648

    Last Modified: 21 Nov 2024

    An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.

    Published: 22 Mar 2019
    8.8
    High

    CVE-2019-9939

    Last Modified: 21 Nov 2024

    The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to bypass authentication by trying to fetch a non-existing page. When the non-existing page is requested, the application responds with a 200 status code and empty page, and adds the requesting client device into the list of recognized devices.

    Published: 22 Mar 2019
    5.3
    Medium

    CVE-2019-9938

    Last Modified: 21 Nov 2024

    The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfer is initiated) to download arbitrary files from the device including contacts, photos, videos, sound clips, etc. The attacker must be authenticated as a "recognized device."

    Published: 22 Mar 2019
    9.8
    Critical

    CVE-2019-9927

    Last Modified: 21 Nov 2024

    Caret before 2019-02-22 allows Remote Code Execution.

    Published: 22 Mar 2019
    6.1
    Medium

    CVE-2019-9925

    Last Modified: 21 Nov 2024

    S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.

    Published: 22 Mar 2019
    8.8
    High

    CVE-2019-9813

    Last Modified: 25 Nov 2025

    Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

    Published: 22 Mar 2019
    8.8
    High

    CVE-2019-9810

    Last Modified: 25 Nov 2025

    Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

    Published: 22 Mar 2019
    5.8
    Medium

    CVE-2019-3877

    Last Modified: 21 Nov 2024

    A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.

    Published: 22 Mar 2019
    9
    Critical

    CVE-2019-10063

    Last Modified: 21 Nov 2024

    Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to prevent sandboxed apps from using the TIOCSTI ioctl, which could otherwise be used to inject commands into the controlling terminal so that they would be executed outside the sandbox after the sandboxed app exits. This fix was incomplete: on 64-bit platforms, the seccomp filter could be bypassed by an ioctl request number that has TIOCSTI in its 32 least significant bits and an arbitrary nonzero value in its 32 most significant bits, which the Linux kernel would treat as equivalent to TIOCSTI.

    Published: 22 Mar 2019
    8.8
    High

    CVE-2019-9956

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a denial of service or code execution via a crafted image file.

    Published: 22 Mar 2019
    7.5
    High

    CVE-2020-27778

    Last Modified: 21 Nov 2024

    A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.

    Published: 22 Mar 2019
    6.5
    Medium

    CVE-2020-18839

    Last Modified: 21 Nov 2024

    Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.

    Published: 22 Mar 2019
    6.1
    Medium

    CVE-2019-9915

    Last Modified: 21 Nov 2024

    GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9914

    Last Modified: 21 Nov 2024

    The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9913

    Last Modified: 21 Nov 2024

    The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9912

    Last Modified: 21 Nov 2024

    The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9911

    Last Modified: 21 Nov 2024

    The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap-reposter&action=edit item XSS.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9910

    Last Modified: 21 Nov 2024

    The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9909

    Last Modified: 21 Nov 2024

    The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.

    Published: 21 Mar 2019
    6.1
    Medium

    CVE-2019-9908

    Last Modified: 21 Nov 2024

    The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.

    Published: 21 Mar 2019
    7.8
    High

    CVE-2018-18913

    Last Modified: 21 Nov 2024

    Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system from any location within the system. The issue lies in the loading of the shcore.dll and dcomp.dll files: these files are being searched for by the program in the same system-wide directory where the HTML file is executed.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2018-20034

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

    Published: 21 Mar 2019
    8.8
    High

    CVE-2019-7539

    Last Modified: 21 Nov 2024

    A code injection issue was discovered in ipycache through 2016-05-31.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2018-20032

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2018-20031

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down.

    Published: 21 Mar 2019
    6.5
    Medium

    CVE-2019-3871

    Last Modified: 21 Nov 2024

    A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response

    Published: 21 Mar 2019
    9.1
    Critical

    CVE-2019-8351

    Last Modified: 21 Nov 2024

    Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2019-7537

    Last Modified: 21 Nov 2024

    An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execution.

    Published: 21 Mar 2019
    8.8
    High

    CVE-2015-6458

    Last Modified: 21 Nov 2024

    Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.

    Published: 21 Mar 2019
    8.8
    High

    CVE-2015-6457

    Last Modified: 21 Nov 2024

    Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.

    Published: 21 Mar 2019
    7.5
    High

    CVE-2018-13798

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V14), SICAM A8000 CP-802X (All versions < V14), SICAM A8000 CP-8050 (All versions < V2.00). Specially crafted network packets sent to port 80/TCP or 443/TCP could allow an unauthenticated remote attacker to cause a Denial-of-Service condition of the web server. The security vulnerability could be exploited by an attacker with network access to the affected systems on port 80/TCP or 443/TCP. Successful exploitation requires no system privileges and no user interaction. An attacker could use the vulnerability to compromise availability of the web server. A system reboot is required to recover the web service of the device. At the time of advisory update, exploit code for this security vulnerability is public.

    Published: 21 Mar 2019
    5.4
    Medium

    CVE-2015-6462

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2019-5490

    Last Modified: 21 Nov 2024

    Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.

    Published: 21 Mar 2019
    5.4
    Medium

    CVE-2015-6461

    Last Modified: 21 Nov 2024

    Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.

    Published: 21 Mar 2019
    —
    Unknown

    CVE-2019-0198

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2019. Notes: none

    Published: 21 Mar 2019
    5.9
    Medium

    CVE-2019-8997

    Last Modified: 21 Nov 2024

    An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could allow an attacker to potentially read arbitrary local files from the application server or make requests on the network by entering maliciously crafted XML in an existing field.

    Published: 21 Mar 2019
    8.1
    High

    CVE-2017-16255

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request at At 0x9d014e84 the value for the cmd1 key is copied using strcpy to the buffer at $sp+0x280. This buffer is 16 bytes large.

    Published: 21 Mar 2019
    8.1
    High

    CVE-2017-16254

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request at 0x9d014e4c the value for the flg key is copied using strcpy to the buffer at $sp+0x270. This buffer is 16 bytes large, sending anything longer will cause a buffer overflow.

    Published: 21 Mar 2019
    8.1
    High

    CVE-2017-16253

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012 for the cc channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request At 0x9d014dd8 the value for the id key is copied using strcpy to the buffer at $sp+0x290. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.

    Published: 21 Mar 2019
    9.8
    Critical

    CVE-2019-7238

    Last Modified: 6 Nov 2025

    Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

    Published: 21 Mar 2019
    7
    High

    CVE-2018-3968

    Last Modified: 21 Nov 2024

    An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.

    Published: 21 Mar 2019