CVE Feed

    Dashboard / CVE

    —
    Unknown

    CVE-2018-15341

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15342

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15346

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15343

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15344

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15345

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15347

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15349

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    —
    Unknown

    CVE-2018-15348

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2018. Notes: none

    Published: 12 Feb 2019
    9.8
    Critical

    CVE-2018-19645

    Last Modified: 21 Nov 2024

    An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

    Published: 12 Feb 2019
    7.5
    High

    CVE-2018-5499

    Last Modified: 21 Nov 2024

    ATTO FibreBridge 7500N firmware version 2.95 is susceptible to a vulnerability which allows attackers to cause a Denial of Service (DoS).

    Published: 12 Feb 2019
    5.3
    Medium

    CVE-2019-7550

    Last Modified: 21 Nov 2024

    In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.

    Published: 12 Feb 2019
    7.1
    High

    CVE-2019-1688

    Last Modified: 21 Nov 2024

    A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, local attacker to gain unauthorized access or cause a Denial of Service (DoS) condition on the server. The vulnerability is due to a fault in the password management system of NAE. An attacker could exploit this vulnerability by authenticating with the default administrator password via the CLI of an affected server. A successful exploit could allow the attacker to view potentially sensitive information or bring the server down, causing a DoS condition. This vulnerability affects Cisco Network Assurance Engine (NAE) Release 3.0(1). The default password condition only affects new installations of Release 3.0(1).

    Published: 12 Feb 2019
    7.2
    High

    CVE-2019-6549

    Last Modified: 21 Nov 2024

    An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP.

    Published: 12 Feb 2019
    6.1
    Medium

    CVE-2019-7739

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Configuration. This is intended behavior. However, it might be unexpected for the user because the configuration dialog lacks an additional message to explain this.

    Published: 12 Feb 2019
    6.1
    Medium

    CVE-2019-7740

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList) could lead to an XSS attack vector.

    Published: 12 Feb 2019
    6.1
    Medium

    CVE-2019-7741

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed stored XSS.

    Published: 12 Feb 2019
    6.1
    Medium

    CVE-2019-7742

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with specific file types and browser-side MIME-type sniffing, causes an XSS attack vector.

    Published: 12 Feb 2019
    9.8
    Critical

    CVE-2019-7743

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.

    Published: 12 Feb 2019
    6.1
    Medium

    CVE-2019-7744

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lead to an XSS vulnerability.

    Published: 12 Feb 2019
    9.8
    Critical

    CVE-2019-6527

    Last Modified: 21 Nov 2024

    PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.

    Published: 12 Feb 2019
    9.1
    Critical

    CVE-2019-6533

    Last Modified: 21 Nov 2024

    Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).

    Published: 12 Feb 2019
    6.1
    Medium

    CVE-2019-7753

    Last Modified: 21 Nov 2024

    Verydows 2.0 has XSS via the index.php?m=api&c=stats&a=count referrer parameter.

    Published: 12 Feb 2019
    5.5
    Medium

    CVE-2019-5595

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentially allowing some kernel data used in the system call to be exposed.

    Published: 12 Feb 2019
    8.8
    High

    CVE-2019-5596

    Last Modified: 21 Nov 2024

    In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.

    Published: 12 Feb 2019
    5.4
    Medium

    CVE-2019-3923

    Last Modified: 21 Nov 2024

    Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-supplied input. An authenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a user's browser session. Tenable has released Nessus 8.2.2 to address this issue.

    Published: 12 Feb 2019
    5.9
    Medium

    CVE-2019-0657

    Last Modified: 21 Nov 2024

    A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

    Published: 12 Feb 2019
    4.3
    Medium

    CVE-2018-18511

    Last Modified: 21 Nov 2024

    Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

    Published: 12 Feb 2019
    4.2
    Medium

    CVE-2019-3828

    Last Modified: 21 Nov 2024

    Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

    Published: 12 Feb 2019
    6.5
    Medium

    CVE-2019-5785

    Last Modified: 21 Nov 2024

    Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 12 Feb 2019
    6.5
    Medium

    CVE-2019-7090

    Last Modified: 21 Nov 2024

    Flash Player Desktop Runtime versions 32.0.0.114 and earlier, Flash Player for Google Chrome versions 32.0.0.114 and earlier, and Flash Player for Microsoft Edge and Internet Explorer 11 versions 32.0.0.114 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Feb 2019
    6.5
    Medium

    CVE-2018-9594

    Last Modified: 21 Nov 2024

    In llcp_link_proc_agf_pdu of llcp_link.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116791157.

    Published: 11 Feb 2019
    6.5
    Medium

    CVE-2018-9593

    Last Modified: 21 Nov 2024

    In llcp_dlc_proc_i_pdu of llcp_dlc.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116722267.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2018-9592

    Last Modified: 21 Nov 2024

    In mca_ccb_hdl_rsp of mca_cact.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116319076.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2018-9591

    Last Modified: 21 Nov 2024

    In bta_hh_ctrl_dat_act of bta_hh_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116108738.

    Published: 11 Feb 2019
    7.5
    High

    CVE-2018-9590

    Last Modified: 21 Nov 2024

    In add_attr of sdp_discovery.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-115900043.

    Published: 11 Feb 2019
    5.5
    Medium

    CVE-2018-9589

    Last Modified: 21 Nov 2024

    In ieee802_11_rx_wnmsleep_req of wnm_ap.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi driver with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111893132.

    Published: 11 Feb 2019
    6.5
    Medium

    CVE-2018-9588

    Last Modified: 21 Nov 2024

    In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111450156.

    Published: 11 Feb 2019
    7.3
    High

    CVE-2018-9587

    Last Modified: 21 Nov 2024

    In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to files within the contact app due to a confused deputy scenario. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Android ID: A-113597344.

    Published: 11 Feb 2019
    7
    High

    CVE-2018-9586

    Last Modified: 21 Nov 2024

    In run of InstallPackageTask.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, it is possible that package verification is turned off and remains off due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-116754444.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-9585

    Last Modified: 21 Nov 2024

    In nfc_ncif_proc_get_routing of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-117554809.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-9584

    Last Modified: 21 Nov 2024

    In nfc_ncif_set_config_status of nfc_ncif.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-114047681.

    Published: 11 Feb 2019
    9.8
    Critical

    CVE-2018-9583

    Last Modified: 21 Nov 2024

    In bta_ag_parse_cmer of bta_ag_cmd.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-112860487.

    Published: 11 Feb 2019
    7.8
    High

    CVE-2018-9582

    Last Modified: 21 Nov 2024

    In package installer in Android-8.0, Android-8.1 and Android-9, there is a possible bypass of the unknown source warning due to a confused deputy scenario. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-112031362.

    Published: 11 Feb 2019
    6.5
    Medium

    CVE-2019-7738

    Last Modified: 21 Nov 2024

    C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.

    Published: 11 Feb 2019
    6.1
    Medium

    CVE-2018-20242

    Last Modified: 21 Nov 2024

    A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.

    Published: 11 Feb 2019
    8.8
    High

    CVE-2019-7737

    Last Modified: 21 Nov 2024

    A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step=submit.

    Published: 11 Feb 2019
    5.3
    Medium

    CVE-2019-6489

    Last Modified: 21 Nov 2024

    Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.

    Published: 11 Feb 2019
    9.6
    Critical

    CVE-2019-7747

    Last Modified: 21 Nov 2024

    DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.

    Published: 11 Feb 2019
    6.1
    Medium

    CVE-2019-7748

    Last Modified: 21 Nov 2024

    _includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.

    Published: 11 Feb 2019