Latest CVE Feed
-
5.5
MEDIUMCVE-2019-0314
SAP Work Manager, versions: 6.3, 6.4, 6.5 and SAP Inventory Manager, version 4.3, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.... Read more
- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-11947
The txrx stats req might be double freed in the pdev detach when the host driver is unloading in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music... Read more
Affected Products : qca6574au_firmware ipq8064_firmware qca9886_firmware qca9980_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820a_firmware sd_835_firmware +74 more products- Published: Jun. 14, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-2004
In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-13048
kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allocation patterns (involving PAGE_SIZE, and a value less than PAGE_SIZE).... Read more
Affected Products : toaruos- Published: Jun. 29, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-11828
Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : office- Published: Jun. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-13291
In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftops tool. It might allow an attacker to cause Information Di... Read more
Affected Products : xpdfreader- Published: Jul. 04, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-2104
In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo... Read more
Affected Products : android- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-2113
In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset protection bypass with no additional privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android... Read more
Affected Products : android- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-2117
In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier systems with no additional execution privileges needed. User ... Read more
Affected Products : android- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-12912
Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application.... Read more
Affected Products : shift- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-1010252
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in... Read more
Affected Products : open_network_operating_system- Published: Jul. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10992
Delta Electronics CNCSoft ScreenEditor, Versions 1.00.89 and prior. Multiple out-of-bounds read vulnerabilities may cause information disclosure due to lacking user input validation for processing project files.... Read more
Affected Products : cnssoft_screeneditor- Published: Jul. 24, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10974
NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitrary code.... Read more
Affected Products : energyplus- Published: Jul. 26, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20870
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14394
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14409
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).... Read more
Affected Products : cpanel- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10345
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.... Read more
Affected Products : configuration_as_code- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-10362
Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system configuration to obtain the values of e... Read more
Affected Products : configuration_as_code- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14334
An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated Certificate and RSA Private Key extraction through an insecure sslcert-get.cgi HTTP command.... Read more
Affected Products : 6600-ap_firmware dwl-3600ap_firmware dwl-8610ap_firmware 6600-ap dwl-3600ap dwl-8610ap- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20902
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024