High · CVSS 8.6
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
Published Feb 28, 2020 · Updated Aug 5, 2024
Medium · CVSS 5
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device Manager, Hitachi Tiered Storage Manager, Hitachi Replication Manager, Hitachi Tuning Manager, Hitachi Global Link Manager and Hitachi Compute Systems Manager.
Published Feb 14, 2020 · Updated Aug 5, 2024
Medium · CVSS 4.3
A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hitachi Compute Systems Manager.
Published Feb 14, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Frog CMS 0.9.5 provides a directory listing for a /public request.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing szLineConv bounds checking.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 return value is mishandled.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
Published Feb 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GPAC version 0.7.1 and earlier has a Buffer Overflow vulnerability in the gf_sm_load_init function in scene_manager.c in libgpac_static.a.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitized when exported to a CSV file. This can result in remote code execution for the attacker.
Published Feb 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
Published Feb 12, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
Published Feb 17, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the size argument in tpdbg_write in drivers/input/touchscreen/ft5x46/ft5x46_ts.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GPAC version 0.7.1 and earlier has a buffer overflow vulnerability in the cat_multiple_files function in applications/mp4box/fileimport.c when MP4Box is used for a local directory containing crafted filenames.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.
Published Feb 21, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Traq 3.7.1 allows SQL Injection via a tickets?search= URI.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.
Published Feb 22, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
Published Feb 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.
Published Feb 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.
Published Feb 8, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1).
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has several integer overflows because of a left-shifting operation when the right-hand operand can be equal to or greater than the integer length. This can be exploited by a crafted application for denial of service.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Secure boot bypass and memory extraction can be achieved on Neato Botvac Connected 2.2.0 devices. During startup, the AM335x secure boot feature decrypts and executes firmware. Secure boot can be bypassed by starting with certain commands to the USB serial port. Although a power cycle occurs, this does not completely reset the chip: memory contents are still in place. Also, it restarts into a boot menu that enables XMODEM upload and execution of an unsigned QNX IFS system image, thereby completing the bypass of secure boot. Moreover, the attacker can craft custom IFS data and write it to unused memory to extract all memory contents that had previously been present. This includes the original firmware and sensitive information such as Wi-Fi credentials.
Published Feb 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in base/PdfFiltersPrivate.cpp.
Published Feb 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In WinRAR versions prior to and including 5.60, There is an out-of-bounds write vulnerability during parsing of a crafted LHA / LZH archive formats. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Published Feb 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell.
Published Feb 21, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability.
Published Feb 21, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression Denial of Service (ReDoS) issue allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to a value containing a long digit string. (The UAP-Core project contains the vulnerability, propagating to all implementations.)
Published Feb 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Gurock TestRail 5.6.0.3853. An "Unrestricted Upload of File" vulnerability exists in the image-upload form (available in the description editor), allowing remote authenticated users to execute arbitrary code by uploading an image file with an executable extension but a safe Content-Type value, and then accessing it via a direct request to the file in the file-upload directory (if it's accessible according to the server configuration).
Published Feb 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.
Published Feb 20, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary web scripts or HTML via the username parameter to the Login Form.
Published Feb 23, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with certain restrictions) that will be executed on behalf of the attacker, via the viewUrl parameter of the "export the dashboard as an image" feature. This could be leveraged to provide a proxy to attack other servers (internal or external) or to perform network scans of external or internal networks.
Published Feb 11, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Published Feb 5, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
Published Feb 28, 2019 · Updated Aug 5, 2024