CVE Feed

    Dashboard / CVE

    3.7
    Low

    CVE-2019-2426

    Last Modified: 21 Nov 2024

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

    Published: 15 Jan 2019
    5.5
    Medium

    CVE-2019-2436

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).

    Published: 15 Jan 2019
    4.9
    Medium

    CVE-2019-2486

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 15 Jan 2019
    4.9
    Medium

    CVE-2019-2495

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 15 Jan 2019
    4.9
    Medium

    CVE-2019-2530

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

    Published: 15 Jan 2019
    6.5
    Medium

    CVE-2019-2533

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data. CVSS 3.0 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).

    Published: 15 Jan 2019
    5
    Medium

    CVE-2019-2536

    Last Modified: 21 Nov 2024

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:N/A:H).

    Published: 15 Jan 2019
    6.1
    Medium

    CVE-2019-6267

    Last Modified: 21 Nov 2024

    The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is mishandled during log viewing at the templates/admin/redirect-log.php URI.

    Published: 15 Jan 2019
    6.5
    Medium

    CVE-2019-6283

    Last Modified: 21 Nov 2024

    In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp.

    Published: 14 Jan 2019
    5.4
    Medium

    CVE-2019-6278

    Last Modified: 21 Nov 2024

    XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.

    Published: 14 Jan 2019
    5.9
    Medium

    CVE-2018-1956

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 153628.

    Published: 14 Jan 2019
    6.1
    Medium

    CVE-2018-1967

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 153748.

    Published: 14 Jan 2019
    9
    Critical

    CVE-2018-1969

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager 6.0.0 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 153750.

    Published: 14 Jan 2019
    9.8
    Critical

    CVE-2019-6259

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter.

    Published: 14 Jan 2019
    9.8
    Critical

    CVE-2019-6256

    Last Modified: 21 Nov 2024

    A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.

    Published: 14 Jan 2019
    7.7
    High

    CVE-2019-6257

    Last Modified: 21 Nov 2024

    A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.

    Published: 14 Jan 2019
    9.8
    Critical

    CVE-2019-3773

    Last Modified: 4 Sept 2026

    Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

    Published: 14 Jan 2019
    9.8
    Critical

    CVE-2019-3774

    Last Modified: 1 Sept 2026

    Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

    Published: 14 Jan 2019
    6.5
    Medium

    CVE-2019-6285

    Last Modified: 3 Nov 2025

    The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

    Published: 14 Jan 2019
    3.3
    Low

    CVE-2019-3815

    Last Modified: 21 Nov 2024

    A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Red Hat Enterprise since v219-62.2.

    Published: 14 Jan 2019
    6.5
    Medium

    CVE-2019-6284

    Last Modified: 21 Nov 2024

    In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp.

    Published: 14 Jan 2019
    6.5
    Medium

    CVE-2019-6286

    Last Modified: 21 Nov 2024

    In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_import(), a similar issue to CVE-2018-11693.

    Published: 14 Jan 2019
    0
    Low

    CVE-2018-20710

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-6285. Reason: This candidate is a duplicate of CVE-2019-6285. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2019-6285 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Jan 2019
    9.8
    Critical

    CVE-2019-3772

    Last Modified: 21 Nov 2024

    Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

    Published: 14 Jan 2019
    5.4
    Medium

    CVE-2018-20703

    Last Modified: 21 Nov 2024

    CubeCart 6.2.2 has Reflected XSS via a /{ADMIN-FILE}/ query string.

    Published: 13 Jan 2019
    8.8
    High

    CVE-2019-6249

    Last Modified: 21 Nov 2024

    An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/index.php?load=admins&act=edit_info&act_type=add.

    Published: 13 Jan 2019
    8.8
    High

    CVE-2019-6245

    Last Modified: 21 Nov 2024

    An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call itself recursively. There can be a situation where (x2 - x1) is always bigger than dx_limit during the recursion, leading to continual stack consumption.

    Published: 13 Jan 2019
    6.1
    Medium

    CVE-2019-6248

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demonstrated by restaurants-details.php.

    Published: 13 Jan 2019
    9.8
    Critical

    CVE-2019-6246

    Last Modified: 21 Nov 2024

    An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library in Boost, the return code is used as an address, leading to an Access Violation because of an out-of-bounds read.

    Published: 13 Jan 2019
    8.8
    High

    CVE-2019-6247

    Last Modified: 21 Nov 2024

    An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflow bug in svgpp_agg_render may lead to code execution. In the render_scanlines_aa_solid function, the blend_hline function is called repeatedly multiple times. blend_hline is equivalent to a loop containing write operations. Each call writes a piece of heap data, and multiple calls overwrite the data in the heap.

    Published: 13 Jan 2019
    6.1
    Medium

    CVE-2018-16206

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in WordPress plugin spam-byebye 2.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jan 2019
    6.1
    Medium

    CVE-2019-6243

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI).

    Published: 12 Jan 2019
    8.8
    High

    CVE-2019-6244

    Last Modified: 21 Nov 2024

    An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL statements, and consequently execute arbitrary PHP code by writing that code into a .php file.

    Published: 12 Jan 2019
    4.5
    Medium

    CVE-2019-3803

    Last Modified: 21 Nov 2024

    Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.

    Published: 12 Jan 2019
    5.5
    Medium

    CVE-2019-7665

    Last Modified: 21 Nov 2024

    In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

    Published: 12 Jan 2019
    6.1
    Medium

    CVE-2017-18635

    Last Modified: 21 Nov 2024

    An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

    Published: 12 Jan 2019
    8.1
    High

    CVE-2018-16886

    Last Modified: 21 Nov 2024

    etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4169

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, an out-of-bounds read was addressed with improved input validation.

    Published: 11 Jan 2019
    5.5
    Medium

    CVE-2018-4179

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.4, there was an issue with the handling of smartcard PINs. This issue was addressed with additional logic.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2018-4186

    Last Modified: 21 Nov 2024

    In Safari before 11.1, an information leakage issue existed in the handling of downloads in Safari Private Browsing. This issue was addressed with additional validation.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4194

    Last Modified: 21 Nov 2024

    In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4207

    Last Modified: 21 Nov 2024

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4210

    Last Modified: 21 Nov 2024

    In iOS before 11.3, Safari before 11.1, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, an array indexing issue existed in the handling of a function in javascript core. This issue was addressed with improved checks.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4212

    Last Modified: 21 Nov 2024

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

    Published: 11 Jan 2019
    8.8
    High

    CVE-2018-4213

    Last Modified: 21 Nov 2024

    In iOS before 11.3, Safari before 11.1, iCloud for Windows before 7.4, tvOS before 11.3, watchOS before 4.3, iTunes before 12.7.4 for Windows, unexpected interaction causes an ASSERT failure. This issue was addressed with improved checks.

    Published: 11 Jan 2019
    7.5
    High

    CVE-2018-4217

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, a privacy issue in the handling of Open Directory records was addressed with improved indexing.

    Published: 11 Jan 2019
    5.5
    Medium

    CVE-2018-4255

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

    Published: 11 Jan 2019
    5.5
    Medium

    CVE-2018-4256

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4257

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.

    Published: 11 Jan 2019
    9.8
    Critical

    CVE-2018-4258

    Last Modified: 21 Nov 2024

    In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.

    Published: 11 Jan 2019