CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-5774

    Last Modified: 21 Nov 2024

    Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.

    Published: 29 Jan 2019
    7.8
    High

    CVE-2019-5780

    Last Modified: 21 Nov 2024

    Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-7151

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was discovered in wasm::Module::getFunctionOrNull in wasm/wasm.cpp in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-7153

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.

    Published: 29 Jan 2019
    9.8
    Critical

    CVE-2018-18500

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

    Published: 29 Jan 2019
    9.8
    Critical

    CVE-2018-18501

    Last Modified: 21 Nov 2024

    Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

    Published: 29 Jan 2019
    7.5
    High

    CVE-2019-9640

    Last Modified: 21 Nov 2024

    An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-1003005

    Last Modified: 21 Nov 2024

    A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5754

    Last Modified: 21 Nov 2024

    Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5756

    Last Modified: 21 Nov 2024

    Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5762

    Last Modified: 21 Nov 2024

    Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5768

    Last Modified: 21 Nov 2024

    DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5770

    Last Modified: 21 Nov 2024

    Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5773

    Last Modified: 21 Nov 2024

    Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.

    Published: 29 Jan 2019
    4.3
    Medium

    CVE-2019-5779

    Last Modified: 21 Nov 2024

    Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-9633

    Last Modified: 21 Nov 2024

    gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).

    Published: 29 Jan 2019
    8.1
    High

    CVE-2019-5755

    Last Modified: 21 Nov 2024

    Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5758

    Last Modified: 21 Nov 2024

    Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Jan 2019
    9.6
    Critical

    CVE-2019-5759

    Last Modified: 21 Nov 2024

    Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5760

    Last Modified: 21 Nov 2024

    Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5761

    Last Modified: 21 Nov 2024

    Incorrect object lifecycle management in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5764

    Last Modified: 21 Nov 2024

    Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 Jan 2019
    5.5
    Medium

    CVE-2019-5765

    Last Modified: 21 Nov 2024

    An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5766

    Last Modified: 21 Nov 2024

    Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5767

    Last Modified: 21 Nov 2024

    Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5771

    Last Modified: 21 Nov 2024

    An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5775

    Last Modified: 21 Nov 2024

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5776

    Last Modified: 21 Nov 2024

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5777

    Last Modified: 21 Nov 2024

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5778

    Last Modified: 21 Nov 2024

    A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-5781

    Last Modified: 21 Nov 2024

    Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

    Published: 29 Jan 2019
    8.8
    High

    CVE-2019-5782

    Last Modified: 21 Nov 2024

    Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-7152

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2019-7154

    Last Modified: 21 Nov 2024

    The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

    Published: 29 Jan 2019
    7.5
    High

    CVE-2019-9208

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.

    Published: 29 Jan 2019
    6.5
    Medium

    CVE-2018-19721

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Note: A different vulnerability than CVE-2018-19723.

    Published: 28 Jan 2019
    7.5
    High

    CVE-2018-19723

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. Note: A different vulnerability than CVE-2018-19721.

    Published: 28 Jan 2019
    6.5
    Medium

    CVE-2018-19010

    Last Modified: 21 Nov 2024

    Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending the malformed network packet, an attacker may be able to disrupt patient monitoring by causing the monitor to repeatedly reboot until it falls back to default configuration and loses network connectivity.

    Published: 28 Jan 2019
    6.5
    Medium

    CVE-2018-19014

    Last Modified: 21 Nov 2024

    Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the location of the monitor, and wired network configuration.

    Published: 28 Jan 2019
    8.1
    High

    CVE-2019-3462

    Last Modified: 21 Nov 2024

    Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

    Published: 28 Jan 2019
    7.8
    High

    CVE-2018-19012

    Last Modified: 21 Nov 2024

    Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take control of the operating system.

    Published: 28 Jan 2019
    9.8
    Critical

    CVE-2019-6991

    Last Modified: 21 Nov 2024

    A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.

    Published: 28 Jan 2019
    5.4
    Medium

    CVE-2019-6990

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a crafted Zone NAME to the index.php?view=zones&action=zoneImage&mid=1 URI.

    Published: 28 Jan 2019
    6.1
    Medium

    CVE-2019-6992

    Last Modified: 21 Nov 2024

    A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaScript code in a vulnerable field via a long NAME or PROTOCOL to the index.php?view=controlcaps URI.

    Published: 28 Jan 2019
    7.3
    High

    CVE-2018-19015

    Last Modified: 21 Nov 2024

    An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application.

    Published: 28 Jan 2019
    6.1
    Medium

    CVE-2018-19724

    Last Modified: 21 Nov 2024

    Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 28 Jan 2019
    7.5
    High

    CVE-2019-3813

    Last Modified: 21 Nov 2024

    Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.

    Published: 28 Jan 2019
    6.1
    Medium

    CVE-2018-19727

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 28 Jan 2019
    6.1
    Medium

    CVE-2018-19726

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 28 Jan 2019
    6.5
    Medium

    CVE-2018-19728

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 28 Jan 2019