CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2019-17343

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging incorrect use of the HVM physmap concept for PV domains.

    Published: 5 Mar 2019
    6.5
    Medium

    CVE-2019-17344

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-17346

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because of an incompatibility between Process Context Identifiers (PCID) and TLB flushes.

    Published: 5 Mar 2019
    6.5
    Medium

    CVE-2019-17348

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Process Context Identifiers (PCID) and shadow-pagetable switching.

    Published: 5 Mar 2019
    7.4
    High

    CVE-2019-8320

    Last Modified: 21 Nov 2024

    A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-8322

    Last Modified: 21 Nov 2024

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-8321

    Last Modified: 21 Nov 2024

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.

    Published: 5 Mar 2019
    8.8
    High

    CVE-2019-8324

    Last Modified: 21 Nov 2024

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

    Published: 5 Mar 2019
    7.5
    High

    CVE-2019-8325

    Last Modified: 21 Nov 2024

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

    Published: 5 Mar 2019
    3.3
    Low

    CVE-2020-18442

    Last Modified: 10 Jul 2025

    Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".

    Published: 5 Mar 2019
    5.1
    Medium

    CVE-2019-0816

    Last Modified: 21 Nov 2024

    A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.

    Published: 5 Mar 2019
    6.5
    Medium

    CVE-2019-11498

    Last Modified: 21 Nov 2024

    WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data.

    Published: 5 Mar 2019
    5.3
    Medium

    CVE-2018-5482

    Last Modified: 21 Nov 2024

    NetApp SnapCenter Server prior to 4.1 does not set the secure flag for a sensitive cookie in an HTTPS session which can allow the transmission of the cookie in plain text over an unencrypted channel.

    Published: 4 Mar 2019
    4.8
    Medium

    CVE-2017-15515

    Last Modified: 21 Nov 2024

    NetApp SnapCenter Server prior to 4.0 is susceptible to cross site scripting vulnerability that could allow a privileged user to inject arbitrary scripts into the custom secondary policy label field.

    Published: 4 Mar 2019
    10
    Critical

    CVE-2019-6235

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3, iTunes 12.9.3 for Windows. A sandboxed process may be able to circumvent sandbox restrictions.

    Published: 4 Mar 2019
    9.8
    Critical

    CVE-2019-6206

    Last Modified: 21 Nov 2024

    An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.3. Password autofill may fill in passwords after they were manually cleared.

    Published: 4 Mar 2019
    9.8
    Critical

    CVE-2019-9566

    Last Modified: 21 Nov 2024

    FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.

    Published: 4 Mar 2019
    6.1
    Medium

    CVE-2019-9567

    Last Modified: 21 Nov 2024

    The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.

    Published: 4 Mar 2019
    6.5
    Medium

    CVE-2019-9568

    Last Modified: 21 Nov 2024

    The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.

    Published: 4 Mar 2019
    9.1
    Critical

    CVE-2019-9565

    Last Modified: 21 Nov 2024

    Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal NTLM hashes or perform SMB relay attacks upon a direct launch of the product, or upon an indirect launch via an integration such as Chrome, Firefox, Word, Outlook, etc. This occurs because the product attempts to access a share with the PLUG-INS subdomain name; an attacker may be able to use Active Directory Domain Services to register that name.

    Published: 4 Mar 2019
    7.5
    High

    CVE-2019-9563

    Last Modified: 21 Nov 2024

    In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.

    Published: 4 Mar 2019
    9.8
    Critical

    CVE-2019-9552

    Last Modified: 21 Nov 2024

    Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or p2p/images/ URI.

    Published: 4 Mar 2019
    4.8
    Medium

    CVE-2019-9551

    Last Modified: 21 Nov 2024

    An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS.

    Published: 4 Mar 2019
    7.8
    High

    CVE-2019-2025

    Last Modified: 21 Nov 2024

    In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-116855682References: Upstream kernel

    Published: 4 Mar 2019
    7.5
    High

    CVE-2018-11793

    Last Modified: 21 Nov 2024

    When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

    Published: 4 Mar 2019
    6.5
    Medium

    CVE-2019-10714

    Last Modified: 21 Nov 2024

    LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.

    Published: 4 Mar 2019
    7.5
    High

    CVE-2019-10897

    Last Modified: 21 Nov 2024

    In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-ieee80211.c by detecting cases in which the bit offset does not advance.

    Published: 4 Mar 2019
    8.8
    High

    CVE-2019-9549

    Last Modified: 21 Nov 2024

    An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstrated by adding a level=1 account, a similar issue to CVE-2018-18935.

    Published: 3 Mar 2019
    4.8
    Medium

    CVE-2019-9550

    Last Modified: 21 Nov 2024

    DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS.

    Published: 3 Mar 2019
    6.5
    Medium

    CVE-2019-9735

    Last Modified: 21 Nov 2024

    An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

    Published: 3 Mar 2019
    6.1
    Medium

    CVE-2019-8278

    Last Modified: 21 Nov 2024

    Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.

    Published: 2 Mar 2019
    5.4
    Medium

    CVE-2019-8279

    Last Modified: 21 Nov 2024

    Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.

    Published: 2 Mar 2019
    5.5
    Medium

    CVE-2019-9857

    Last Modified: 21 Nov 2024

    In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c neglects to call fsnotify_put_mark() with IN_MASK_CREATE after fsnotify_find_mark(), which will cause a memory leak (aka refcount leak). Finally, this will cause a denial of service.

    Published: 2 Mar 2019
    9.8
    Critical

    CVE-2019-9546

    Last Modified: 21 Nov 2024

    SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

    Published: 1 Mar 2019
    5.3
    Medium

    CVE-2019-9547

    Last Modified: 21 Nov 2024

    In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains.

    Published: 1 Mar 2019
    8.8
    High

    CVE-2019-9544

    Last Modified: 21 Nov 2024

    An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() located in Core/Ap4Array.h. It can be triggered by sending a crafted file to (for example) the mp42hls binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

    Published: 1 Mar 2019
    7.8
    High

    CVE-2018-8790

    Last Modified: 21 Nov 2024

    Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM.

    Published: 1 Mar 2019
    7.5
    High

    CVE-2018-20798

    Last Modified: 21 Nov 2024

    The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.

    Published: 1 Mar 2019
    7.5
    High

    CVE-2018-20799

    Last Modified: 21 Nov 2024

    In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access restrictions.

    Published: 1 Mar 2019
    7.5
    High

    CVE-2019-9484

    Last Modified: 21 Nov 2024

    The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."

    Published: 1 Mar 2019
    9.1
    Critical

    CVE-2019-9483

    Last Modified: 21 Nov 2024

    Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.

    Published: 1 Mar 2019
    5.3
    Medium

    CVE-2019-9482

    Last Modified: 21 Nov 2024

    In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires access to the event that has received the sighting. The issue affects instances with restrictive sighting settings (event only / sighting reported only).

    Published: 1 Mar 2019
    6.5
    Medium

    CVE-2019-5786

    Last Modified: 24 Oct 2025

    Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 1 Mar 2019
    7.5
    High

    CVE-2019-10899

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.

    Published: 1 Mar 2019
    5.5
    Medium

    CVE-2019-9824

    Last Modified: 21 Nov 2024

    tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

    Published: 1 Mar 2019
    5.6
    Medium

    CVE-2018-1890

    Last Modified: 13 Feb 2025

    IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.

    Published: 1 Mar 2019
    7.5
    High

    CVE-2019-0200

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance by sending specially crafted commands using AMQP protocol versions below 1.0 (AMQP 0-8, 0-9, 0-91 and 0-10). Users of Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 utilizing AMQP protocols 0-8, 0-9, 0-91, 0-10 must upgrade to Qpid Broker-J versions 7.0.7 or 7.1.1 or later.

    Published: 1 Mar 2019
    7.4
    High

    CVE-2019-12439

    Last Modified: 21 Nov 2024

    bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code.

    Published: 1 Mar 2019
    5.5
    Medium

    CVE-2019-6547

    Last Modified: 21 Nov 2024

    Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.84 and prior. An out-of-bounds read vulnerability may cause the software to crash due to lacking user input validation for processing project files.

    Published: 28 Feb 2019
    7.5
    High

    CVE-2019-6551

    Last Modified: 21 Nov 2024

    Pangea Communications Internet FAX ATA all Versions 3.1.8 and prior allow an attacker to bypass user authentication using a specially crafted URL to cause the device to reboot, which may be used to cause a continual denial-of-service condition.

    Published: 28 Feb 2019