Unknown · CVSS Not scored
An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server listening on the port 80. The /httpapi.asp endpoint of the GoAhead web server was also vulnerable to multiple command execution vulnerabilities.
Published Jul 1, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined with one of the many /httpapi.asp endpoint command-execution security issues, the DNS rebinding attack could allow an attacker to compromise the victim device from the Internet.
Published Jul 1, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.
Published Jul 1, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.
Published Jul 6, 2020 · Updated Aug 5, 2024
High · CVSS 7.2
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality.
Published Jul 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
Published Jul 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server) sends crafted text to a serial port (that has logging enabled), the text will be replayed when the logs are viewed. Exploiting this vulnerability requires access to the serial port and/or console server.
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow.
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
Published Jul 30, 2019 · Updated Aug 5, 2024
Critical · CVSS 9.8
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value provided in the DTLS message.
Published Jul 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
Published Jul 31, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
Published Jul 30, 2019 · Updated Aug 5, 2024
High · CVSS 7.2
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to DNS functionality.
Published Jul 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to cause a denial of service via a crafted file.
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
Published Jul 30, 2019 · Updated Aug 5, 2024
Medium · CVSS 5.9
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.
Published Jul 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.
Published Jul 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
Published Jul 29, 2019 · Updated Aug 5, 2024
Critical · CVSS 9.1
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.
Published Jul 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
Published Jul 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
Published Jul 30, 2019 · Updated Aug 5, 2024