CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2018-1899

    Last Modified: 21 Nov 2024

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow an attacker to change one of the settings related to InfoSphere Business Glossary Anywhere due to improper access control. IBM X-Force ID: 152528.

    Published: 5 Mar 2019
    4.4
    Medium

    CVE-2018-1937

    Last Modified: 21 Nov 2024

    IBM Cloud Private 3.1.1 could alllow a local user with administrator privileges to intercept highly sensitive unencrypted data. IBM X-Force ID: 153317.

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-6223

    Last Modified: 20 Dec 2025

    A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

    Published: 5 Mar 2019
    6.7
    Medium

    CVE-2018-19639

    Last Modified: 21 Nov 2024

    If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6212

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6215

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-6219

    Last Modified: 21 Nov 2024

    A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. Processing a maliciously crafted message may lead to a denial of service.

    Published: 5 Mar 2019
    6.1
    Medium

    CVE-2019-6229

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to universal cross site scripting.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6233

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    2.8
    Low

    CVE-2018-19637

    Last Modified: 21 Nov 2024

    Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection

    Published: 5 Mar 2019
    2.2
    Low

    CVE-2018-19638

    Last Modified: 21 Nov 2024

    In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.

    Published: 5 Mar 2019
    4.4
    Medium

    CVE-2018-19640

    Last Modified: 21 Nov 2024

    If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6202

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, watchOS 5.1.3. A malicious application may be able to elevate privileges.

    Published: 5 Mar 2019
    5.5
    Medium

    CVE-2019-6209

    Last Modified: 21 Nov 2024

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to determine kernel memory layout.

    Published: 5 Mar 2019
    8.6
    High

    CVE-2019-6214

    Last Modified: 21 Nov 2024

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6221

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, iTunes 12.9.3 for Windows. A malicious application may be able to elevate privileges.

    Published: 5 Mar 2019
    6.1
    Medium

    CVE-2019-6228

    Last Modified: 21 Nov 2024

    A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue is fixed in iOS 12.1.3, Safari 12.0.3. Processing maliciously crafted web content may lead to a cross site scripting attack.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6200

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. An attacker in a privileged network position may be able to execute arbitrary code.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6205

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.

    Published: 5 Mar 2019
    5.5
    Medium

    CVE-2019-6208

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6210

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6211

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6213

    Last Modified: 21 Nov 2024

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6216

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6217

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6218

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.

    Published: 5 Mar 2019
    5.5
    Medium

    CVE-2019-6220

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Mojave 10.14.3. An application may be able to read restricted memory.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6224

    Last Modified: 21 Nov 2024

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-6225

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to elevate privileges.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6226

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6227

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    8.6
    High

    CVE-2019-6230

    Last Modified: 21 Nov 2024

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3,macOS Mojave 10.14.3,tvOS 12.1.2,watchOS 5.1.3. A malicious application may be able to break out of its sandbox.

    Published: 5 Mar 2019
    5.5
    Medium

    CVE-2019-6231

    Last Modified: 21 Nov 2024

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to read restricted memory.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-6234

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 5 Mar 2019
    7.3
    High

    CVE-2018-19636

    Last Modified: 21 Nov 2024

    Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-8259

    Last Modified: 21 Nov 2024

    UltraVNC revision 1198 contains multiple memory leaks (CWE-655) in VNC client code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1199.

    Published: 5 Mar 2019
    9.8
    Critical

    CVE-2019-8260

    Last Modified: 21 Nov 2024

    UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.

    Published: 5 Mar 2019
    9.8
    Critical

    CVE-2019-8262

    Last Modified: 21 Nov 2024

    UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. This attack appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1204.

    Published: 5 Mar 2019
    9.8
    Critical

    CVE-2019-8258

    Last Modified: 21 Nov 2024

    UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.

    Published: 5 Mar 2019
    9.8
    Critical

    CVE-2019-8261

    Last Modified: 21 Nov 2024

    UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multiplication overflow. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.

    Published: 5 Mar 2019
    6.5
    Medium

    CVE-2019-8263

    Last Modified: 21 Nov 2024

    UltraVNC revision 1205 has stack-based buffer overflow vulnerability in VNC client code inside ShowConnInfo routine, which leads to a denial of service (DoS) condition. This attack appear to be exploitable via network connectivity. User interaction is required to trigger this vulnerability. This vulnerability has been fixed in revision 1206.

    Published: 5 Mar 2019
    9.8
    Critical

    CVE-2018-15361

    Last Modified: 21 Nov 2024

    UltraVNC revision 1198 has a buffer underflow vulnerability in VNC client code, which can potentially result in code execution. This attack appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1199.

    Published: 5 Mar 2019
    4.8
    Medium

    CVE-2019-9570

    Last Modified: 21 Nov 2024

    An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.

    Published: 5 Mar 2019
    7.2
    High

    CVE-2019-9572

    Last Modified: 21 Nov 2024

    SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using the .zip extension along with the _Static substring, changing the Content-Type to application/zip, and placing PHP code after the ZIP header. This ultimately allows execution of arbitrary PHP code in Public\Home\1_Static.php because of mishandling in the Application\Admin\Controller\ThemeController.class.php Upload() function.

    Published: 5 Mar 2019
    6.5
    Medium

    CVE-2019-17345

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-8323

    Last Modified: 21 Nov 2024

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.

    Published: 5 Mar 2019
    7
    High

    CVE-2019-17342

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a race condition that arose when XENMEM_exchange was introduced.

    Published: 5 Mar 2019
    0
    Low

    CVE-2019-10124

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-10903

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.

    Published: 5 Mar 2019
    7.8
    High

    CVE-2019-17341

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.

    Published: 5 Mar 2019