CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-7815

    Last Modified: 21 Nov 2024

    A Type Confusion (CWE-843) vulnerability exists in Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0) on c3core.dll which could cause remote code to be executed when parsing a GD1 file

    Published: 6 Feb 2019
    —
    Unknown

    CVE-2018-17203

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Feb 2019
    —
    Unknown

    CVE-2018-20246

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 6 Feb 2019
    5.4
    Medium

    CVE-2019-7545

    Last Modified: 21 Nov 2024

    In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name field.

    Published: 6 Feb 2019
    7.8
    High

    CVE-2018-3976

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write exists in the CALS Raster file format-parsing functionality of Canvas Draw version 5.0.0.28. A specially crafted CAL image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a CAL image to trigger this vulnerability and gain code execution.

    Published: 6 Feb 2019
    7.8
    High

    CVE-2018-3980

    Last Modified: 21 Nov 2024

    An exploitable out-of-bounds write exists in the TIFF-parsing functionality of Canvas Draw version 5.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.

    Published: 6 Feb 2019
    6.8
    Medium

    CVE-2019-6517

    Last Modified: 21 Nov 2024

    BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Professional Operating System US release does not properly enforce user access control to privileged accounts, which may allow for unauthorized access to administrative level functions.

    Published: 6 Feb 2019
    4.8
    Medium

    CVE-2019-7547

    Last Modified: 21 Nov 2024

    An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name containing an XSS Payload, leading to stored XSS.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2019-7543

    Last Modified: 21 Nov 2024

    In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.

    Published: 6 Feb 2019
    5.4
    Medium

    CVE-2019-7544

    Last Modified: 21 Nov 2024

    An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripting (XSS) vulnerability in the User Name Field.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2019-7546

    Last Modified: 21 Nov 2024

    An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) vulnerability.

    Published: 6 Feb 2019
    7.8
    High

    CVE-2018-3973

    Last Modified: 21 Nov 2024

    An exploitable out of bounds write exists in the CAL parsing functionality of Canvas Draw version 5.0.0. A specially crafted CAL image processed via the application can lead to an out of bounds write overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.

    Published: 6 Feb 2019
    9.8
    Critical

    CVE-2019-3464

    Last Modified: 21 Nov 2024

    Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

    Published: 6 Feb 2019
    9.8
    Critical

    CVE-2019-3463

    Last Modified: 21 Nov 2024

    Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2015-9282

    Last Modified: 21 Nov 2024

    The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2018-20755

    Last Modified: 21 Nov 2024

    MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2018-20757

    Last Modified: 21 Nov 2024

    MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.

    Published: 6 Feb 2019
    5.4
    Medium

    CVE-2018-20758

    Last Modified: 21 Nov 2024

    MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2018-20756

    Last Modified: 21 Nov 2024

    MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-1003006

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.0 and earlier in src/main/java/hudson/plugins/groovy/StringScriptSource.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-1003008

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.

    Published: 6 Feb 2019
    5.3
    Medium

    CVE-2019-1003017

    Last Modified: 21 Nov 2024

    A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load the imported job's configuration.

    Published: 6 Feb 2019
    9.1
    Critical

    CVE-2019-1003015

    Last Modified: 21 Nov 2024

    An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins) queried in preparation of job import to read arbitrary files, perform a denial of service attack, etc.

    Published: 6 Feb 2019
    5.9
    Medium

    CVE-2019-1003019

    Last Modified: 21 Nov 2024

    An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

    Published: 6 Feb 2019
    4.3
    Medium

    CVE-2019-1003020

    Last Modified: 21 Nov 2024

    A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.

    Published: 6 Feb 2019
    4.3
    Medium

    CVE-2019-1003021

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlier in OicSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.

    Published: 6 Feb 2019
    6.5
    Medium

    CVE-2019-1003022

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2019-1003023

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourcePrinter.java, src/main/java/io/jenkins/plugins/analysis/core/util/Sanitizer.java, src/main/java/io/jenkins/plugins/analysis/warnings/DuplicateCodeScanner.java that allows attackers with the ability to control warnings parser input to have Jenkins render arbitrary HTML.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-1003007

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Jenkins Warnings Plugin 5.0.0 and earlier in src/main/java/hudson/plugins/warnings/GroovyParser.java that allows attackers to execute arbitrary code via a form validation HTTP endpoint.

    Published: 6 Feb 2019
    7.4
    High

    CVE-2019-1003009

    Last Modified: 21 Nov 2024

    An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java, src/main/java/hudson/plugins/active_directory/ActiveDirectorySecurityRealm.java, src/main/java/hudson/plugins/active_directory/ActiveDirectoryUnixAuthenticationProvider.java that allows attackers to impersonate the Active Directory server Jenkins connects to for authentication if Jenkins is configured to use StartTLS.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-1003016

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java, src/main/java/org/jenkins/ci/plugins/jobimport/model/JenkinsSite.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 6 Feb 2019
    4.3
    Medium

    CVE-2019-1003018

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.

    Published: 6 Feb 2019
    8.1
    High

    CVE-2019-7578

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-7575

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.

    Published: 6 Feb 2019
    6.3
    Medium

    CVE-2019-3825

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could bypass the lock screen by selecting the timed login user and waiting for the timer to expire, at which time they would gain access to the logged-in user's session.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-7572

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-7577

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.

    Published: 6 Feb 2019
    7.5
    High

    CVE-2018-16890

    Last Modified: 15 Apr 2026

    libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.

    Published: 6 Feb 2019
    9.8
    Critical

    CVE-2019-3822

    Last Modified: 15 Apr 2026

    libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.

    Published: 6 Feb 2019
    4.3
    Medium

    CVE-2019-3823

    Last Modified: 15 Apr 2026

    libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.

    Published: 6 Feb 2019
    6.5
    Medium

    CVE-2019-5784

    Last Modified: 21 Nov 2024

    Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Feb 2019
    6.1
    Medium

    CVE-2019-6504

    Last Modified: 21 Nov 2024

    Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object.

    Published: 6 Feb 2019
    8.8
    High

    CVE-2019-7573

    Last Modified: 21 Nov 2024

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the wNumCoef loop).

    Published: 6 Feb 2019
    7.8
    High

    CVE-2018-18333

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations.

    Published: 5 Feb 2019
    7.5
    High

    CVE-2018-18334

    Last Modified: 21 Nov 2024

    A vulnerability in the Private Browser of Trend Micro Dr. Safety for Android (Consumer) versions below 3.0.1478 could allow an remote attacker to bypass the Same Origin Policy (SOP) and obtain sensitive information via crafted JavaScript code on vulnerable installations.

    Published: 5 Feb 2019
    4.3
    Medium

    CVE-2018-3989

    Last Modified: 21 Nov 2024

    An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400).A specially crafted IRP request can cause the driver to return uninitialized memory, resulting in kernel memory disclosure. An attacker can send an IRP request to trigger this vulnerability.

    Published: 5 Feb 2019
    9.3
    Critical

    CVE-2018-3990

    Last Modified: 21 Nov 2024

    An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, potentially, privilege escalation. An attacker can send an IRP request to trigger this vulnerability.

    Published: 5 Feb 2019
    10
    Critical

    CVE-2018-3991

    Last Modified: 21 Nov 2024

    An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can send a malformed TCP packet to trigger this vulnerability.

    Published: 5 Feb 2019
    8.8
    High

    CVE-2018-18503

    Last Modified: 21 Nov 2024

    When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.

    Published: 5 Feb 2019
    9.8
    Critical

    CVE-2019-6519

    Last Modified: 21 Nov 2024

    WebAccess/SCADA, Version 8.3. An improper authentication vulnerability exists that could allow a possible authentication bypass allowing an attacker to upload malicious data.

    Published: 5 Feb 2019