LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 11 of 31.

Unknown · CVSS Not scored

CVE-2019-15311: An issue was discovered on Zolo Halo devices via the Linkplay firmware.

An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server listening on the port 80. The /httpapi.asp endpoint of the GoAhead web server was also vulnerable to multiple command execution vulnerabilities.

Published Jul 1, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-15312: An issue was discovered on Zolo Halo devices via the Linkplay firmware.

An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The device was found to be vulnerable to DNS rebinding. Combined with one of the many /httpapi.asp endpoint command-execution security issues, the DNS rebinding attack could allow an attacker to compromise the victim device from the Internet.

Published Jul 1, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-15310: An issue was discovered on various devices via the Linkplay firmware.

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

Published Jul 1, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14900: A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1.

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks.

Published Jul 6, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14456: Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial...

Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging. If a malicious user of an external system (connected to a serial port on an Opengear console server) sends crafted text to a serial port (that has logging enabled), the text will be replayed when the logs are viewed. Exploiting this vulnerability requires access to the serial port and/or console server.

Published Jul 31, 2019 · Updated Aug 5, 2024

Critical · CVSS 9.8

CVE-2019-14431: In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to...

In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value provided in the DTLS message.

Published Jul 29, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14441: An issue was discovered in Libav 12.3.

An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv. This is related to ff_mpa_synth_filter_float in avcodec/mpegaudiodsp_template.c. NOTE: This may be a duplicate of CVE-2018-19129

Published Jul 30, 2019 · Updated Aug 5, 2024

Medium · CVSS 5.9

CVE-2019-14415: An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1.

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another user's browser, related to resiliency plans functionality. A victim must open a resiliency plan that an attacker has access to.

Published Jul 29, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14443: An issue was discovered in Libav 12.3.

An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avconv.

Published Jul 30, 2019 · Updated Aug 5, 2024

Critical · CVSS 9.1

CVE-2019-14418: An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1.

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.

Published Jul 29, 2019 · Updated Aug 5, 2024