Latest CVE Feed
-
9.3
CRITICALCVE-2019-10309
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity processing when processing the responses, allowing unauthorized attackers on the same network to read arbit... Read more
Affected Products : self-organizing_swarm_modules- Published: Apr. 30, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-11687
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable ... Read more
Affected Products : dicom_standard- Published: May. 02, 2019
- Modified: Jul. 24, 2025
-
9.3
HIGHCVE-2018-4062
A hard-coded credentials vulnerability exists in the snmpd function of the Sierra Wireless AirLink ES450 FW 4.9.3. Activating snmpd outside of the WebUI can cause the activation of the hard-coded credentials, resulting in the exposure of a privileged user... Read more
- Published: May. 06, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1773
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
Affected Products : webex_meetings_server webex_meetings_online webex_business_suite webex_business_suite_lockdown- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-3567
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said m... Read more
Affected Products : osquery- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1990
In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2016
In NFA_SendRawFrame of nfa_dm_api.cc, there is a possible out-of-bound write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Pro... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-16118
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.... Read more
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2019-1848
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports neces... Read more
- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2106
In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: ... Read more
Affected Products : android- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-12574
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability ... Read more
- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-13637
In LogMeIn join.me before 3.16.0.5505, an attacker could execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows. An attacker could exploit this vulnerability... Read more
Affected Products : join.me- Published: Jul. 17, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-13382
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\Inva... Read more
- Published: Jul. 26, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1927
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-14986
eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticated attackers with access to the web interface, because features such as File-Browser and Shell Command (as well as "Set root password")... Read more
- Published: Aug. 13, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2108
In ihevcd_ref_list of ihevcd_ref_list.c in Android 10, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat... Read more
Affected Products : android- Published: Sep. 05, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2184
In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat... Read more
Affected Products : android- Published: Oct. 11, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2206
In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is needed for exploitation.P... Read more
Affected Products : android- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-15344
The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). ... Read more
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-15595
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.... Read more
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024