CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-20638

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20637

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2018-20636

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.

    Published: 20 Mar 2019
    4.3
    Medium

    CVE-2018-20635

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Advance B2B Script 2.1.4 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20634

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Advance B2B Script 2.1.4 allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field.

    Published: 20 Mar 2019
    8.8
    High

    CVE-2018-20633

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2018-20632

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Advance B2B Script 2.1.4 has stored Cross-Site Scripting (XSS) via the FIRST NAME or LAST NAME field.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2018-20631

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2018-20630

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2018-20629

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

    Published: 20 Mar 2019
    7.5
    High

    CVE-2018-20628

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Charity Foundation Script 1 through 3 allows directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

    Published: 20 Mar 2019
    5.4
    Medium

    CVE-2018-20627

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Consumer Reviews Script 4.0.3 has HTML injection via the search box.

    Published: 20 Mar 2019
    6.5
    Medium

    CVE-2018-20626

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Consumer Reviews Script 4.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.

    Published: 20 Mar 2019
    5.9
    Medium

    CVE-2019-11840

    Last Modified: 18 May 2026

    An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the counter otherwise grows greater than 32 bits, the amd64 implementation will first generate incorrect output, and then cycle back to previously generated keystream. Repeated keystream bytes can lead to loss of confidentiality in encryption applications, or to predictability in CSPRNG applications.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9794

    Last Modified: 25 Nov 2025

    A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third party applications and these applications insufficiently sanitize URL data. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9790

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9788

    Last Modified: 25 Nov 2025

    Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    7.5
    High

    CVE-2018-12545

    Last Modified: 21 Nov 2024

    In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9796

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    7.2
    High

    CVE-2019-9193

    Last Modified: 21 Nov 2024

    In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused to run arbitrary operating system commands on Windows, Linux, and macOS. NOTE: Third parties claim/state this is not an issue because PostgreSQL functionality for ‘COPY TO/FROM PROGRAM’ is acting as intended. References state that in PostgreSQL, a superuser can execute commands as the server user without using the ‘COPY FROM PROGRAM’.

    Published: 20 Mar 2019
    5.9
    Medium

    CVE-2019-9793

    Last Modified: 21 Nov 2024

    A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have explicitly disabled Spectre mitigations. *Note: Spectre mitigations are currently enabled for all users by default settings.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-1010022

    Last Modified: 21 Nov 2024

    GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

    Published: 20 Mar 2019
    5.5
    Medium

    CVE-2020-18768

    Last Modified: 21 Nov 2024

    There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9791

    Last Modified: 25 Nov 2025

    The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-8457

    Last Modified: 21 Nov 2024

    SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9792

    Last Modified: 25 Nov 2025

    The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    9.8
    Critical

    CVE-2019-9795

    Last Modified: 21 Nov 2024

    A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    5.3
    Medium

    CVE-2019-9801

    Last Modified: 21 Nov 2024

    Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

    Published: 20 Mar 2019
    8.1
    High

    CVE-2018-15498

    Last Modified: 21 Nov 2024

    YSoft SafeQ Server 6 allows a replay attack.

    Published: 19 Mar 2019
    9.8
    Critical

    CVE-2018-18473

    Last Modified: 21 Nov 2024

    A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system.

    Published: 19 Mar 2019
    9.8
    Critical

    CVE-2019-6441

    Last Modified: 21 Nov 2024

    An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM3300 5.0.0.55 devices. The password reset functionality of the router doesn't have backend validation for the current password and doesn't require any type of authentication. By making a POST request to the apply.cgi file of the router, the attacker can change the admin username and password of the router.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6282

    Last Modified: 21 Nov 2024

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6279

    Last Modified: 21 Nov 2024

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6729

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7423.

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-6733

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7576.

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-6734

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the setInterval method. By performing actions in JavaScript, an attacker can cause a pointer to be reused after it has been freed. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7452.

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-6728

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7353.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6730

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the popUpMenu method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7368.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6731

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the conversion of HTML files to PDF. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7369.

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-6732

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFParseDateEx method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7453.

    Published: 19 Mar 2019
    6.5
    Medium

    CVE-2019-6735

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7355.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6727

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the XFA remerge method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7347.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6275

    Last Modified: 21 Nov 2024

    Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.

    Published: 19 Mar 2019
    8.8
    High

    CVE-2019-6274

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.

    Published: 19 Mar 2019
    4
    Medium

    CVE-2018-17502

    Last Modified: 21 Nov 2024

    The Receptionist for iPad could allow a local attacker to obtain sensitive information, caused by an error in the contact.json file. An attacker could exploit this vulnerability to obtain the contact names, phone numbers and emails.

    Published: 19 Mar 2019
    2.9
    Low

    CVE-2018-17500

    Last Modified: 21 Nov 2024

    Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of hardcoded OAuth Creds in plaintext. An attacker could exploit this vulnerability to obtain sensitive information.

    Published: 19 Mar 2019
    2.9
    Low

    CVE-2018-17499

    Last Modified: 21 Nov 2024

    Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17497

    Last Modified: 21 Nov 2024

    eVisitorPass contains default administrative credentials. An attacker could exploit this vulnerability to gain full access to the application.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17496

    Last Modified: 21 Nov 2024

    eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error while in kiosk mode. By visiting the kiosk and typing ctrl+shift+esc, an attacker could exploit this vulnerability to open the task manager to kill the process or launch new processes on the system.

    Published: 19 Mar 2019
    8.4
    High

    CVE-2018-17495

    Last Modified: 21 Nov 2024

    eVisitorPass could allow a local attacker to gain elevated privileges on the system, caused by an error with the Virtual Keyboard Help Dialog. By visiting the kiosk and removing the program from fullscreen, an attacker could exploit this vulnerability using the terminal to launch the command prompt.

    Published: 19 Mar 2019