9base — 9base |
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. |
2019-11-21 |
not yet calculated |
CVE-2014-1935 MISC MISC MISC |
ace — ace |
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges. |
2019-11-22 |
not yet calculated |
CVE-2014-6311 MISC MISC MISC MISC |
angularjs — angularjs |
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto__` payload. |
2019-11-19 |
not yet calculated |
CVE-2019-10768 MISC |
apache — nifi |
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to. |
2019-11-19 |
not yet calculated |
CVE-2019-10083 CONFIRM |
apple — iphone_3gs |
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka ‘alloc8’. An attacker with physical access to the device can install arbitrary firmware. |
2019-11-22 |
not yet calculated |
CVE-2019-9536 MISC MISC |
asus — rt-ac66u_firmware |
Stack-based buffer overflow in Asuswrt-Merlin firmware for ASUS devices older than 384.4 and ASUS firmware before 3.0.0.4.382.50470 for devices allows remote attackers to execute arbitrary code by providing a long string to the blocking.asp page via a GET or POST request. Vulnerable parameters are flag, mac, and cat_id. |
2019-11-21 |
not yet calculated |
CVE-2018-8879 MISC MISC |
beckhoff — twincat_runtime |
When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached by sending a malformed UDP packet to the device. |
2019-11-21 |
not yet calculated |
CVE-2019-5637 MISC CONFIRM |
beckhoff — twincat_runtime |
When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the TwinCAT devices are still performing as normal. |
2019-11-21 |
not yet calculated |
CVE-2019-5636 MISC CONFIRM |
belkin — linksys_velop_devices |
Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI. |
2019-11-21 |
not yet calculated |
CVE-2019-16340 MISC MISC MISC |
blackboard — blackboard_learn |
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page. |
2019-11-18 |
not yet calculated |
CVE-2018-13257 MISC |
centreon — web |
Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron. |
2019-11-21 |
not yet calculated |
CVE-2019-16406 MISC MISC |
centreon — web |
Centreon Web 19.04.4 allows Remote Code Execution by an administrator who can modify Macro Expression location settings. |
2019-11-21 |
not yet calculated |
CVE-2019-16405 MISC MISC MISC |
chyrp — chyrp |
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php. |
2019-11-21 |
not yet calculated |
CVE-2012-1001 MISC MISC MISC MISC MISC MISC |
cloud_foundry_foundation — cloud_foundry_routing |
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthorized malicious user could forge a route service request using an invalid nonce that will cause the Gorouter to crash. |
2019-11-19 |
not yet calculated |
CVE-2019-11289 CONFIRM |
cog — galaxy_client_service |
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy versions before 1.2.60 and all corresponding versions of GOG Galaxy 2.0 Beta are affected. |
2019-11-21 |
not yet calculated |
CVE-2019-15511 MISC MISC |
cumin — cumin |
cumin: At installation postgresql database user created without password |
2019-11-21 |
not yet calculated |
CVE-2012-3460 MISC MISC |
d-link — dsl-6740u_gateway |
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding, (2) Port Triggering Entries, (3) URL Filters in Parental Control, (4) Print Server settings, (5) QoS Queue Setup, or (6) QoS Classification Entries. |
2019-11-22 |
not yet calculated |
CVE-2013-6811 MISC MISC |
drupal — drupal |
A cross-site request forgery (CSRF) vulnerability in the Activity module 6.x-1.x for Drupal. |
2019-11-22 |
not yet calculated |
CVE-2012-2079 MISC MISC |
drupal — drupal |
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal. |
2019-11-21 |
not yet calculated |
CVE-2012-1637 MISC MISC |
drupal — drupal |
Cross-site scripting (XSS) vulnerability in the Activity module 6.x-1.x for Drupal. |
2019-11-21 |
not yet calculated |
CVE-2012-2078 MISC MISC |
e-deploy — e-deploy |
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data |
2019-11-21 |
not yet calculated |
CVE-2014-3700 MISC MISC |
embedthis — goahead |
Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limited length and can overflow. This can cause a copy of the Host header to fail, leaving that buffer uninitialized, which may leak uninitialized data in a response. |
2019-11-22 |
not yet calculated |
CVE-2019-19240 MISC MISC MISC |
eracent — epa_agent |
An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be used to start external programs with elevated permissions because of an Untrusted Search Path. |
2019-11-22 |
not yet calculated |
CVE-2019-17446 CONFIRM |
eracent — multiple_linux_agents |
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following. |
2019-11-22 |
not yet calculated |
CVE-2019-17445 CONFIRM |
exis-ti — contexis |
Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter in a detail action. |
2019-11-22 |
not yet calculated |
CVE-2013-6239 MISC MISC MISC |
flashcanvas — flashcanvas |
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header. |
2019-11-22 |
not yet calculated |
CVE-2013-6880 MISC MISC MISC MISC |
fortinet — forticlient_for_mac |
An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security check. |
2019-11-21 |
not yet calculated |
CVE-2019-17650 CONFIRM |
fortinet — forticlient_for_mac |
A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in the console window when the user connects to an SSL VPN Gateway. |
2019-11-21 |
not yet calculated |
CVE-2019-15704 CONFIRM |
fortinet — fortios |
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users’ passwords (except the administrator’s password), private keys’ passphrases and High Availability password (when set). |
2019-11-21 |
not yet calculated |
CVE-2019-6693 CONFIRM |
gitlab — gitlab |
GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments. |
2019-11-22 |
not yet calculated |
CVE-2019-15593 MISC |
gnu — c_library |
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program. |
2019-11-19 |
not yet calculated |
CVE-2019-19126 MISC |
gnu — gnusound |
gnusound 0.7.5 has format string issue |
2019-11-19 |
not yet calculated |
CVE-2012-0824 MISC MISC MISC MISC |
hotkeyp — hotkeyp |
HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp. |
2019-11-21 |
not yet calculated |
CVE-2019-18349 MISC MISC MISC |
hp — thinpro |
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. |
2019-11-22 |
not yet calculated |
CVE-2019-18909 CONFIRM |
hp — thinpro |
The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges. |
2019-11-22 |
not yet calculated |
CVE-2019-18910 CONFIRM |
hp — thinpro |
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands. |
2019-11-22 |
not yet calculated |
CVE-2019-16286 CONFIRM |
hp — thinpro |
An attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose presence puts the device in Administrative Mode, which will allow the attacker to executed commands with elevated privileges. |
2019-11-22 |
not yet calculated |
CVE-2019-16287 CONFIRM |
hp — thinpro |
If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive. |
2019-11-22 |
not yet calculated |
CVE-2019-16285 CONFIRM |
ibm — tivoli_netcool_impact |
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 166719. |
2019-11-22 |
not yet calculated |
CVE-2019-4569 XF CONFIRM |
ibm — tivoli_netcool_impact |
IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720. |
2019-11-22 |
not yet calculated |
CVE-2019-4570 XF CONFIRM |
ikiwiki — ikiwiki |
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi. |
2019-11-21 |
not yet calculated |
CVE-2015-2793 MISC MISC MISC MISC MISC MISC MISC MISC MISC |
iobroker — iobroker.js-controller |
An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like “admin”. It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the authentication is enabled (by default isn’t enabled). |
2019-11-21 |
not yet calculated |
CVE-2019-10767 MISC |
jalios — jcms |
Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges via a backdoor account, by using any username and the hardcoded dev password. |
2019-11-21 |
not yet calculated |
CVE-2019-19033 MISC MISC MISC |
jenkins — jenkins |
Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |
2019-11-21 |
not yet calculated |
CVE-2019-16542 MLIST CONFIRM |
jenkins — jenkins |
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. |
2019-11-21 |
not yet calculated |
CVE-2019-16543 MLIST CONFIRM |
jenkins — jenkins |
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope. |
2019-11-21 |
not yet calculated |
CVE-2019-16541 MLIST CONFIRM |
jenkins — jenkins |
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts. |
2019-11-21 |
not yet calculated |
CVE-2019-16538 MLIST CONFIRM |
joomla! — joomla! |
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message. |
2019-11-22 |
not yet calculated |
CVE-2013-6879 MISC |
joomla! — joomla! |
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to component/mijosearch/search. |
2019-11-22 |
not yet calculated |
CVE-2013-6878 MISC |
kyrol_security_labs — kyrol_internet_security |
IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402401 using METHOD_NEITHER results in a read primitive. |
2019-11-21 |
not yet calculated |
CVE-2019-19197 MISC MISC |
lexmark — services_monitor |
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system. |
2019-11-21 |
not yet calculated |
CVE-2019-16758 MISC MISC |
libarchive — libarchive |
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. |
2019-11-21 |
not yet calculated |
CVE-2019-19221 MISC MISC |
lightdm — lightdm |
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation. |
2019-11-19 |
not yet calculated |
CVE-2011-3349 MISC MISC MISC MISC MISC MISC |
linux_foundation — foomatic-rip_filter |
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. |
2019-11-19 |
not yet calculated |
CVE-2011-2923 MISC MISC MISC MISC |
linux_foundation — foomatic-rip_filter |
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. |
2019-11-19 |
not yet calculated |
CVE-2011-2924 MISC MISC MISC MISC MISC MISC |
linux — linux_kernel |
In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c, as demonstrated by unregister_snap_client, aka CID-9804501fa122. |
2019-11-22 |
not yet calculated |
CVE-2019-19227 MISC MISC |
loftek — nexus_543_ip_camera |
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi. |
2019-11-21 |
not yet calculated |
CVE-2013-3314 MISC MISC MISC |
loftek — nexus_543_ip_camera |
Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request. |
2019-11-21 |
not yet calculated |
CVE-2013-3311 MISC MISC MISC |
loftek — nexus_543_ip_camera |
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal vulnerability in CVE-2013-3311. |
2019-11-21 |
not yet calculated |
CVE-2013-3313 MISC MISC MISC |
loftek — nexus_543_ip_camera |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi. |
2019-11-21 |
not yet calculated |
CVE-2013-3312 MISC MISC |
masqmail — masqmail |
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. |
2019-11-19 |
not yet calculated |
CVE-2011-3350 MISC MISC MISC |
mcafee — client_proxy |
Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key on the client which should only be generated by the network administrator. |
2019-11-22 |
not yet calculated |
CVE-2019-3654 MISC |
myphpadmin — myphpadmin |
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. |
2019-11-22 |
not yet calculated |
CVE-2019-18622 CONFIRM |
naver — vaccine |
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive. |
2019-11-22 |
not yet calculated |
CVE-2019-13157 CONFIRM |
netapp — ontap_select_deploy |
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account. |
2019-11-21 |
not yet calculated |
CVE-2019-5509 CONFIRM |
netapp — ontap_select_deploy |
All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges. |
2019-11-21 |
not yet calculated |
CVE-2019-17272 CONFIRM |
newbee-mall — newbee-mall |
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection. |
2019-11-18 |
not yet calculated |
CVE-2019-19113 MISC |
nginx — nginx |
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) |
2019-11-19 |
not yet calculated |
CVE-2011-4968 MISC MISC MISC MISC MISC MISC MISC |
nitro_software — nitro_pro |
Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed. |
2019-11-21 |
not yet calculated |
CVE-2019-18958 MISC |
nlnet_labs — unbound |
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `–enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration. |
2019-11-19 |
not yet calculated |
CVE-2019-18934 MLIST MISC MISC CONFIRM |
nsslglobal_technologies — satlink_vsat_modem_unit_devices |
The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn’t properly sanitize input for error messages, leading to the ability to inject client-side code. |
2019-11-22 |
not yet calculated |
CVE-2019-15652 MISC MISC |
nusphere — nusoap |
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. |
2019-11-19 |
not yet calculated |
CVE-2012-6071 MISC MISC MISC MISC |
oniguruma — oniguruma |
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read. |
2019-11-21 |
not yet calculated |
CVE-2019-19203 MISC MISC |
oniguruma — oniguruma |
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read. |
2019-11-21 |
not yet calculated |
CVE-2019-19204 MISC MISC |
openshift-origin-note_gem_for_ruby_on_rails — openshift-origin-note_gem_for_ruby_on_rails |
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. |
2019-11-21 |
not yet calculated |
CVE-2014-0084 MISC |
openstack — designate |
Designate does not enforce the DNS protocol limit concerning record set sizes |
2019-11-22 |
not yet calculated |
CVE-2015-5694 MISC MISC MISC MISC |
ovirt — ovirt |
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center |
2019-11-22 |
not yet calculated |
CVE-2015-1780 MISC MISC |
owncloud — owncloud |
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/calendar/ajax/event/new.php or (2) url parameter to apps/bookmarks/ajax/addBookmark.php. |
2019-11-22 |
not yet calculated |
CVE-2013-0203 MISC MISC |
pagekit — pagekit |
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request. |
2019-11-22 |
not yet calculated |
CVE-2019-19013 MISC |
pannellum — pannellum |
In Pannellum from 2.5.0 through 2.5.4 URLs were not sanitized for data URIs (or vbscript:), allowing for potential XSS attacks. Such an attack would require a user to click on a hot spot to execute and would require an attacker-provided configuration. The most plausible potential attack would be if pannellum.htm was hosted on a domain that shared cookies with the targeted site’s user authentication; an |
2019-11-22 |
not yet calculated |
CVE-2019-16763 MISC CONFIRM |
pivotal — rabbitmq_and_rabbitmq_for_pcf |
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information. |
2019-11-22 |
not yet calculated |
CVE-2019-11291 CONFIRM |
pivotal — rabbitmq_and_rabbitmq_for_pivotal_platform |
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The “X-Reason” HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing. |
2019-11-23 |
not yet calculated |
CVE-2019-11287 CONFIRM |
plex — media_server |
Plex Media Server 1.18.2.2029-36236cc4c allows remote attackers to bypass intended access control because X-Plex-Token is mishandled, and can be retrieved from Tautulli. |
2019-11-18 |
not yet calculated |
CVE-2018-21031 MISC MISC |
plow — plow |
plow has local buffer overflow vulnerability |
2019-11-22 |
not yet calculated |
CVE-2012-3407 MISC MISC MISC |
posh — posh_portal |
Multiple cross-site scripting (XSS) vulnerabilities in POSH (aka Posh portal or Portaneo) 3.0 through 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) error parameter to /includes/plugins/mobile/scripts/login.php or (2) id parameter to portal/openrssarticle.php |
2019-11-22 |
not yet calculated |
CVE-2014-2214 MISC MISC |
posh — posh_portal |
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendmd5.php. |
2019-11-22 |
not yet calculated |
CVE-2014-2213 MISC MISC MISC |
postfixadmin — postfixadmin |
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities |
2019-11-22 |
not yet calculated |
CVE-2012-0812 MISC MISC MISC MISC MISC MISC MISC |
powerdns — authoritative_server |
PowerDNS Authoritative daemon , all versions pdns 4.1.x before pdns 4.1.10, exiting when encountering a serial between 2^31 and 2^32-1 while trying to notify a slave leads to DoS. |
2019-11-22 |
not yet calculated |
CVE-2019-10203 CONFIRM |
pyxml — pyxml |
PyXML: Hash table collisions CPU usage Denial of Service |
2019-11-22 |
not yet calculated |
CVE-2012-0877 MISC MISC MISC MISC MISC |
qualcomm — ips |
Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-compatible interpreters due to incorrect buffer size calculation. in PostScript and PDF printers that use IPS versions prior to 2019.2 in PostScript and PDF printers that use IPS versions prior to 2019.2 |
2019-11-21 |
not yet calculated |
CVE-2019-10627 CONFIRM |
qualcomm — multiple_products |
Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, SDA660, SDA845, SDM450, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-10490 CONFIRM |
qualcomm — multiple_products |
Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8017, APQ8053, APQ8096, APQ8096AU, IPQ8074, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, QCA8081, QM215, SDM429, SDM439, SDM450, SDM632, Snapdragon_High_Med_2016 |
2019-11-21 |
not yet calculated |
CVE-2019-2318 CONFIRM |
qualcomm — multiple_products |
Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8939, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, SDM845, SDX20, SDX24, SM6150, SM7150, SM8150 |
2019-11-21 |
not yet calculated |
CVE-2019-10486 CONFIRM |
qualcomm — multiple_products |
Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2289 CONFIRM |
qualcomm — multiple_products |
While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non secure environment. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCS404, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, Snapdragon_High_Med_2016, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2315 CONFIRM |
qualcomm — multiple_products |
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8096AU, APQ8098, MDM9640, MSM8996AU, MSM8998, QCA6574AU, QCN7605, QCS405, QCS605, SDA845, SDM845, SDX20 |
2019-11-21 |
not yet calculated |
CVE-2019-10535 CONFIRM |
qualcomm — multiple_products |
Out-of-bounds access can occur in camera driver due to improper validation of array index in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCN7605, SDA660, SDM450, SDM630, SDM636, SDM660, SDX20 |
2019-11-21 |
not yet calculated |
CVE-2019-10503 CONFIRM |
qualcomm — multiple_products |
Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SDA660, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150 |
2019-11-21 |
not yet calculated |
CVE-2019-2268 CONFIRM |
qualcomm — multiple_products |
Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8053, IPQ4019, IPQ8064, MDM9206, MDM9207C, MDM9607, MSM8909, MSM8909W, Nicobar, QCA9980, QCS405, QCS605, SDM845, SDX24, SM7150, SM8150 |
2019-11-21 |
not yet calculated |
CVE-2019-2266 CONFIRM |
qualcomm — multiple_products |
Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, SDX55, SM6150, SM7150, SM8150, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2336 CONFIRM |
qualcomm — multiple_products |
Buffer overflow can occur while processing non-standard NAN message from user space. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS405, QCS605, SDA660, SDA845, SDM636, SDM660, SDM845, SDX20, SDX24, SM8150 |
2019-11-21 |
not yet calculated |
CVE-2019-2297 CONFIRM |
qualcomm — multiple_products |
Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2339 CONFIRM |
qualcomm — multiple_products |
Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application. in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2329 CONFIRM |
qualcomm — multiple_products |
If a bitmap file is loaded from any un-authenticated source, there is a possibility that the bitmap can potentially cause stack buffer overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8016, APQ8096AU, APQ8098, MDM9205, MSM8996AU, MSM8998, Nicobar, QCS405, QCS605, SA6155P, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2251 CONFIRM |
qualcomm — multiple_products |
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, IPQ8074, MDM9150, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8976, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA8081, QCM2150, QCN7605, QCS404, QCS405, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX55, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2018-13916 CONFIRM |
qualcomm — multiple_products |
Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, MDM9205, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCS404, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, Snapdragon_High_Med_2016, SXR1130 |
2019-11-21 |
not yet calculated |
CVE-2019-2295 CONFIRM |
qualcomm — multiple_products |
Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2271 CONFIRM |
qualcomm — multiple_products |
SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2303 CONFIRM |
qualcomm — multiple_products |
While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8976, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX55, SM6150, SM7150, SM8150, SM8250, Snapdragon_High_Med_2016, SXR1130, SXR2130 |
2019-11-21 |
not yet calculated |
CVE-2019-2335 CONFIRM |
qualcomm — qca6174_9377 |
Low privilege users can access service configuration which contains registry data that admins uses to create or delete entries in the registry in QCA6174_9377.WIN.1.0 in QCA6174_9377 |
2019-11-21 |
not yet calculated |
CVE-2019-10617 CONFIRM |
rconfig — rconfig |
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection. |
2019-11-21 |
not yet calculated |
CVE-2019-19207 MISC |
rc — rc |
rc before 1.7.1-5 insecurely creates temporary files. |
2019-11-21 |
not yet calculated |
CVE-2014-1936 MISC MISC MISC |
red_hat — ansible-playbook_-k_and_ansible_cli_tools |
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them. |
2019-11-22 |
not yet calculated |
CVE-2019-10206 CONFIRM |
red_hat — clouldforms |
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms’s v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field. |
2019-11-22 |
not yet calculated |
CVE-2018-10854 CONFIRM |
red_hat — redhat-upgrade-tool |
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
2019-11-22 |
not yet calculated |
CVE-2014-3585 REDHAT REDHAT |
ros — ros_comm |
An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. A buffer overflow allows attackers to cause a denial of service and possibly execute arbitrary code via an IP address with a long hostname. |
2019-11-22 |
not yet calculated |
CVE-2019-13566 MISC MISC MISC |
ruby_net-ldap_gem_for_ruby_on_rails — ruby_net-ldap_gem_for_ruby_on_rails |
The Ruby net-ldap gem before 0.16.2 uses a weak salt when generating SSHA passwords. |
2019-11-21 |
not yet calculated |
CVE-2014-0083 MISC MISC CONFIRM MISC |
sangoma — asterisk_and_certified_asterisk |
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary system commands. |
2019-11-22 |
not yet calculated |
CVE-2019-18610 MISC MISC |
sangoma — asterisk_and_certified_asterisk |
An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x, 16.x, and 17.x, and Certified Asterisk 13.21, because of an incomplete fix for CVE-2019-18351. A SIP request can be sent to Asterisk that can change a SIP peer’s IP address. A REGISTER does not need to occur, and calls can be hijacked as a result. The only thing that needs to be known is the peer’s name; authentication details such as passwords do not need to be known. This vulnerability is only exploitable when the nat option is set to the default, or auto_force_rport. |
2019-11-22 |
not yet calculated |
CVE-2019-18790 MISC MISC |
sangoma — asterisk_and_certified_asterisk |
An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If it receives a re-invite initiating T.38 faxing and has a port of 0 and no c line in the SDP, a NULL pointer dereference and crash will occur. This is different from CVE-2019-18940. |
2019-11-22 |
not yet calculated |
CVE-2019-18976 CONFIRM MISC MISC MISC MISC |
sangoma — freepbx |
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. |
2019-11-21 |
not yet calculated |
CVE-2019-19006 MISC MISC CONFIRM MISC |
schneider_electric — andover_continuum_devices |
A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702) , which could enable a successful Cross-site Scripting (XSS attack) when using the products web server. |
2019-11-20 |
not yet calculated |
CVE-2019-6853 CONFIRM |
shibboleth — shibboleth_service_provider |
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow. |
2019-11-21 |
not yet calculated |
CVE-2019-19191 MISC MISC |
slackbuilds — slackware |
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges. |
2019-11-21 |
not yet calculated |
CVE-2013-7172 MISC MISC MISC MISC |
slackbuilds — slackware_and_slackware_llvm |
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges. |
2019-11-21 |
not yet calculated |
CVE-2013-7171 MISC MISC MISC MISC |
sniffit — sniffit |
sniffit 0.3.7 and prior: A configuration file can be leveraged to execute code as root |
2019-11-19 |
not yet calculated |
CVE-2014-5439 MISC MISC |
spagobi — spagobi |
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, aka “XSS File Upload.” |
2019-11-22 |
not yet calculated |
CVE-2013-6234 MISC MISC MISC |
symfony — symfony
|
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter. |
2019-11-21 |
not yet calculated |
CVE-2019-11325 CONFIRM MISC CONFIRM CONFIRM |
symfony — symfony |
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x). |
2019-11-21 |
not yet calculated |
CVE-2019-18888 CONFIRM FEDORA FEDORA FEDORA CONFIRM CONFIRM |
symfony — symfony |
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. |
2019-11-21 |
not yet calculated |
CVE-2019-18887 CONFIRM FEDORA FEDORA FEDORA CONFIRM CONFIRM |
symfony — symfony |
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security. |
2019-11-21 |
not yet calculated |
CVE-2019-18886 MISC CONFIRM MISC |
symfony — symfony |
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache. |
2019-11-21 |
not yet calculated |
CVE-2019-18889 CONFIRM FEDORA CONFIRM CONFIRM |
synametrics_technologies — synaman_and_syncrify_and_syntail |
Multiple cross-site request forgery (CSRF) vulnerabilities in Synametrics Technologies SynaMan before 3.5 Build 1451, Syncrify before 3.7 Build 856, and SynTail before 1.5 Build 567 |
2019-11-21 |
not yet calculated |
CVE-2015-3140 CONFIRM CONFIRM CONFIRM |
tenda — ac9_router_ac1200_smart_dual_band_gigabit_wifi_router |
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS1 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability. |
2019-11-21 |
not yet calculated |
CVE-2019-5071 MISC |
tenda — ac9_router_ac1200_smart_dual_band_gigabit_wifi_router |
An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart Dual-Band Gigabit WiFi Route (AC9V1.0 Firmware V15.03.05.16multiTRU). A specially crafted HTTP POST request can cause a command injection in the DNS2 post parameters, resulting in code execution. An attacker can send HTTP POST request with command to trigger this vulnerability. |
2019-11-21 |
not yet calculated |
CVE-2019-5072 MISC |
videolan — libbluray |
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files |
2019-11-22 |
not yet calculated |
CVE-2015-7810 MISC MISC MISC MISC MISC |
vmware — workstation_and_fusion |
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an information disclosure vulnerability in vmnetdhcp. Successful exploitation of this issue may allow an attacker on a guest VM to disclose sensitive information by leaking memory from the host process. |
2019-11-20 |
not yet calculated |
CVE-2019-5540 CONFIRM |
vmware — workstation_and_fusion |
VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition on their own VM. |
2019-11-20 |
not yet calculated |
CVE-2019-5541 CONFIRM |
vtiger — vtiger_crm |
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request. |
2019-11-21 |
not yet calculated |
CVE-2019-19202 MISC |
w3edge — w3_total_cache |
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files. |
2019-11-22 |
not yet calculated |
CVE-2012-6077 MISC MISC MISC MISC CONFIRM |
w3edge — w3_total_cache |
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys. |
2019-11-22 |
not yet calculated |
CVE-2012-6079 MISC MISC MISC CONFIRM |
w3edge — w3_total_cache |
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes. |
2019-11-22 |
not yet calculated |
CVE-2012-6078 MISC MISC MISC CONFIRM |
wolfssl — wolfssl |
wolfssl before 3.2.0 does not properly issue certificates for a server’s hostname. |
2019-11-21 |
not yet calculated |
CVE-2014-2901 MISC MISC |
wolfssl — wolfssl |
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication. |
2019-11-21 |
not yet calculated |
CVE-2014-2904 MISC MISC MISC |
wolfssl — wolfssl |
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates. |
2019-11-21 |
not yet calculated |
CVE-2014-2902 MISC MISC MISC |
xcfa — xcfa |
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. |
2019-11-21 |
not yet calculated |
CVE-2014-5254 MISC MISC MISC MISC MISC |
xcfa — xcfa |
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254. |
2019-11-21 |
not yet calculated |
CVE-2014-5255 MISC MISC MISC MISC MISC MISC |
xcftools — xcftools |
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file. |
2019-11-21 |
not yet calculated |
CVE-2019-5086 MISC MISC |
xcftools — xcftools |
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row’s allocation size, that could be exploited to corrupt memory and eventually execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file. |
2019-11-21 |
not yet calculated |
CVE-2019-5087 MISC MISC |
xlockmore — xlockmore |
xlockmore before 5.43 ‘dclock’ security bypass vulnerability |
2019-11-21 |
not yet calculated |
CVE-2012-4524 MISC MISC MISC MISC MISC MISC MISC MISC MISC MISC |
zhone — znid_2426a |
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference. |
2019-11-21 |
not yet calculated |
CVE-2014-8356 MISC MISC MISC |
zoho_manageengine — opmanager_and_firewall_analyzer |
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload. |
2019-11-21 |
not yet calculated |
CVE-2019-17421 MISC MISC |
zte — xscdn_iamweb |
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users? information leakage. |
2019-11-22 |
not yet calculated |
CVE-2019-3427 CONFIRM |
zte — zxcdn_iamweb |
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker could directly access the management portal in HTTP, resulting in users? information leakage. |
2019-11-22 |
not yet calculated |
CVE-2019-3428 CONFIRM |
zulip — zulip_server |
In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registered their account using social authentication (e.g., GitHub or Google SSO) in an organization that also allows password authentication could have their personal API key stolen by an unprivileged attacker, allowing nearly full access to the user’s account. |
2019-11-21 |
not yet calculated |
CVE-2019-18933 CONFIRM MISC |