LiveActive security incident?Get immediate response
CVE archive

May 2019

Browse CVE records published in May 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1081 matching CVEs · Page 5 of 22.

Unknown · CVSS Not scored

CVE-2019-20806: An issue was discovered in the Linux kernel before 5.2.

An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in drivers/media/pci/tw5864/tw5864-video.c, which may cause denial of service, aka CID-2e7682ebfc75.

Published May 27, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-20795: iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c.

iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.

Published May 9, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-20801: An issue was discovered in the Readdle Documents app before 6.9.7 for iOS.

An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server allows for cross-origin requests from any domain, and the WebSocket server lacks authorization control. Any web site can execute JavaScript code (that accesses a user's data) via cross-origin requests.

Published May 17, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-20390: A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote...

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to remove files on the server without a victim's knowledge, by enticing an authenticated user to visit an attacker's web page. The application fails to validate the CSRF token for a GET request. An attacker can craft a panel/uploads/read.json?cmd=rm URL (removing this token) and send it to the victim.

Published May 15, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19276: A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl.

A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 4). Specially crafted packets sent to port 161/udp can cause the SNMP service of affected devices to crash. A manual restart of the device is required to resume operation of the service.

Published May 12, 2021 · Updated Aug 5, 2024

High · CVSS 7.8

CVE-2019-19164: Dext5 Upload ActiveX Arbitrary File Execution Vulnerability

dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remote files to be executed by setting the arguments to the activex method. A remote attacker could induce a user to access a crafted web page, causing damage such as malicious code infection.

Published May 7, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-18666: An issue was discovered on D-Link DAP-1360 revision F devices.

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested. Versions through 6.12b01 have weak root credentials, allowing an attacker to gain remote root access. After 6.12b01, the root credentials were changed but the telnet service can still be started without authorization.

Published May 15, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-17562: A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack.

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.

Published May 14, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-17572: In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default,...

In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.

Published May 14, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-15083: Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injecte...

Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page.

Published May 14, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14827: A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via...

A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.

Published May 17, 2021 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-13021: The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on th...

The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has generated a password using ENCtool.jar (see CVE-2019-13022). This allows any low-privilege user who can read this file to trivially obtain the passwords for the administrative accounts of the JetSelect application. The path to the file containing the encoded password hash is /opt/JetSelect/SFC/resources/sfc-general-properties.

Published May 14, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13023: An issue was discovered in all versions of Bond JetSelect.

An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so that the credentials are visible.

Published May 14, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13022: Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password gener...

Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plaintext into the 'encrypted' password that is then stored within the database. These steps are able to be trivially reversed, allowing for escalation of privilege within the JetSelect application through obtaining the passwords of JetSelect administrators. JetSelect administrators have the ability to modify and delete all networking configuration across a vessel, as well as altering network configuration of all managed network devices (switches, routers).

Published May 14, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12864: SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, becaus...

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter.

Published May 4, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12483: An issue was discovered in GPAC 0.7.1.

An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

Published May 30, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-12480: BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU La...

BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a malformed DCC in AtomicWriteFile, AtomicReadFile and DeviceCommunicationControl services. An unauthenticated remote attacker could cause a denial of service (bacserv daemon crash) because there is an invalid read in bacdcode.c during parsing of alarm tag numbers.

Published May 30, 2019 · Updated Aug 4, 2024