CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2019-2550

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Logoff Page). The supported version that is affected is 12.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-2554

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

    Published: 16 Jan 2019
    8.2
    High

    CVE-2018-3309

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is prior to 5.2.22. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2018-3303

    Last Modified: 21 Nov 2024

    Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: EM Console). Supported versions that are affected are 13.2 and 13.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

    Published: 16 Jan 2019
    6.3
    Medium

    CVE-2018-3305

    Last Modified: 21 Nov 2024

    Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponent: Load Testing for Web Apps). Supported versions that are affected are 12.5.0.3, 13.1.0.1, 13.2.0.1 and 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data as well as unauthorized read access to a subset of Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6455

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6456

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6457

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6458

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6459

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_extract_type in rec-utils.c in librec.a.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6460

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a.

    Published: 16 Jan 2019
    4.8
    Medium

    CVE-2018-20723

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

    Published: 16 Jan 2019
    4.8
    Medium

    CVE-2018-20724

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

    Published: 16 Jan 2019
    4.8
    Medium

    CVE-2018-20725

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

    Published: 16 Jan 2019
    5.4
    Medium

    CVE-2018-20726

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

    Published: 16 Jan 2019
    10
    Critical

    CVE-2015-9280

    Last Modified: 21 Nov 2024

    MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.

    Published: 16 Jan 2019
    6.1
    Medium

    CVE-2015-9276

    Last Modified: 21 Nov 2024

    SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password.

    Published: 16 Jan 2019
    9.1
    Critical

    CVE-2015-9277

    Last Modified: 21 Nov 2024

    MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.

    Published: 16 Jan 2019
    9.8
    Critical

    CVE-2015-9278

    Last Modified: 21 Nov 2024

    MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.

    Published: 16 Jan 2019
    6.1
    Medium

    CVE-2015-9279

    Last Modified: 21 Nov 2024

    MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

    Published: 16 Jan 2019
    8.1
    High

    CVE-2019-6447

    Last Modified: 21 Nov 2024

    The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.

    Published: 16 Jan 2019
    6.1
    Medium

    CVE-2019-6261

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in com_contact leads to a stored XSS vulnerability.

    Published: 16 Jan 2019
    5.4
    Medium

    CVE-2019-6262

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration helpurl settings allowed stored XSS.

    Published: 16 Jan 2019
    4.8
    Medium

    CVE-2019-6263

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allowed stored XSS.

    Published: 16 Jan 2019
    6.1
    Medium

    CVE-2019-6264

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.9.2. Inadequate escaping in mod_banners leads to a stored XSS vulnerability.

    Published: 16 Jan 2019
    9.1
    Critical

    CVE-2019-6444

    Last Modified: 21 Nov 2024

    An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-controlled data is dereferenced by ntohl() in ntpd.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6445

    Last Modified: 21 Nov 2024

    An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.

    Published: 16 Jan 2019
    6.5
    Medium

    CVE-2019-6442

    Last Modified: 21 Nov 2024

    An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.

    Published: 16 Jan 2019
    9.1
    Critical

    CVE-2019-6443

    Last Modified: 21 Nov 2024

    An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read in read_sysvars in ntp_control.c in ntpd.

    Published: 16 Jan 2019
    9.8
    Critical

    CVE-2019-6440

    Last Modified: 21 Nov 2024

    Zemana AntiMalware before 3.0.658 Beta mishandles update logic.

    Published: 16 Jan 2019
    5.4
    Medium

    CVE-2016-10737

    Last Modified: 21 Nov 2024

    Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.

    Published: 16 Jan 2019
    8.8
    High

    CVE-2016-10738

    Last Modified: 21 Nov 2024

    Zenbership v107 has CSRF via admin/cp-functions/event-add.php.

    Published: 16 Jan 2019
    9.8
    Critical

    CVE-2019-6439

    Last Modified: 21 Nov 2024

    examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.

    Published: 16 Jan 2019
    7.5
    High

    CVE-2018-20720

    Last Modified: 21 Nov 2024

    ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.

    Published: 16 Jan 2019
    7.5
    High

    CVE-2019-9003

    Last Modified: 21 Nov 2024

    In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.

    Published: 16 Jan 2019
    7.2
    High

    CVE-2019-1003004

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.

    Published: 16 Jan 2019
    9.8
    Critical

    CVE-2019-6446

    Last Modified: 21 Jul 2025

    An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

    Published: 16 Jan 2019
    7.8
    High

    CVE-2019-6488

    Last Modified: 21 Nov 2024

    The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which can lead to a segmentation fault or possibly unspecified other impact, as demonstrated by a crash in __memmove_avx_unaligned_erms in sysdeps/x86_64/multiarch/memmove-vec-unaligned-erms.S during a memcpy.

    Published: 16 Jan 2019
    7.2
    High

    CVE-2019-1003003

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.

    Published: 16 Jan 2019
    9.8
    Critical

    CVE-2018-6345

    Last Modified: 21 Nov 2024

    The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other functions. This affects all supported versions of HHVM (3.30.1 and 3.27.5 and below).

    Published: 15 Jan 2019
    5.9
    Medium

    CVE-2019-3554

    Last Modified: 21 Nov 2024

    Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00

    Published: 15 Jan 2019
    9.8
    Critical

    CVE-2019-3557

    Last Modified: 21 Nov 2024

    The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

    Published: 15 Jan 2019
    6.1
    Medium

    CVE-2018-7603

    Last Modified: 21 Nov 2024

    In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). The module doesn't sufficiently filter user-entered text among the autocompletion items leading to a Cross Site Scripting (XSS) vulnerability. This vulnerability can be exploited by any user allowed to create one of the autocompletion item, for instance, nodes, users, comments.

    Published: 15 Jan 2019
    5.9
    Medium

    CVE-2017-6921

    Last Modified: 21 Nov 2024

    In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and allows PATCH requests, and an attacker can get or register a user account on the site with permissions to upload files and to modify the file resource.

    Published: 15 Jan 2019
    5.5
    Medium

    CVE-2019-0009

    Last Modified: 21 Nov 2024

    On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and the packet forwarding engine (PFE). In a virtual chassis (VC) deployment, this issue disrupts communication between the VC members. This issue does not affect other Junos platforms. Affected releases are Junos OS on EX2300 and EX3400 series: 15.1X53 versions prior to 15.1X53-D590; 18.1 versions prior to 18.1R2-S2, 18.1R3; 18.2 versions prior to 18.2R2.

    Published: 15 Jan 2019
    7.5
    High

    CVE-2019-0012

    Last Modified: 21 Nov 2024

    A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker to craft a specific BGP message to cause the routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. This issue only affects PE routers configured with BGP Auto discovery for LDP VPLS. Other BGP configurations are unaffected by this vulnerability. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D81; 12.3 versions prior to 12.3R12-S12; 12.3X48 versions prior to 12.3X48-D76; 14.1X53 versions prior to 14.1X53-D48; 15.1 versions prior to 15.1F6-S12, 15.1R7-S2; 15.1X49 versions prior to 15.1X49-D150; 15.1X53 versions prior to 15.1X53-D235, 15.1X53-D495, 15.1X53-D590, 15.1X53-D68; 16.1 versions prior to 16.1R3-S10, 16.1R4-S12, 16.1R6-S6, 16.1R7-S1; 16.2 versions prior to 16.2R2-S7; 17.1 versions prior to 17.1R2-S9, 17.1R3; 17.2 versions prior to 17.2R1-S7, 17.2R2-S6, 17.2R3; 17.3 versions prior to 17.3R2-S4, 17.3R3; 17.4 versions prior to 17.4R1-S5, 17.4R2; 18.1 versions prior to 18.1R2-S3, 18.1R3.

    Published: 15 Jan 2019
    6.5
    Medium

    CVE-2019-0013

    Last Modified: 21 Nov 2024

    The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is received. While RPD restarts after a crash, repeated crashes can result in an extended Denial of Service (DoS) condition. This issue only affects IPv4 PIM. IPv6 PIM is unaffected by this vulnerability. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77; 12.3X48 versions prior to 12.3X48-D77; 15.1 versions prior to 15.1F6-S10, 15.1R6-S6, 15.1R7; 15.1X49 versions prior to 15.1X49-D150; 15.1X53 versions prior to 15.1X53-D233, 15.1X53-D59; 16.1 versions prior to 16.1R3-S8, 16.1R4-S8, 16.1R7; 16.2 versions prior to 16.2R2-S6; 17.1 versions prior to 17.1R2-S6, 17.1R3; 17.2 versions prior to 17.2R2-S3, 17.2R3; 17.3 versions prior to 17.3R2-S4, 17.3R3; 17.4 versions prior to 17.4R2.

    Published: 15 Jan 2019
    6.5
    Medium

    CVE-2019-0017

    Last Modified: 21 Nov 2024

    The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior to 18.3R1.

    Published: 15 Jan 2019
    10
    Critical

    CVE-2019-0020

    Last Modified: 21 Nov 2024

    Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take full control of any installation of the software. Affected releases are Juniper Networks Juniper ATP: 5.0 versions prior to 5.0.3.

    Published: 15 Jan 2019
    7.1
    High

    CVE-2019-0021

    Last Modified: 21 Nov 2024

    On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.

    Published: 15 Jan 2019