LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 12 of 31.

Unknown · CVSS Not scored

CVE-2019-14371: An issue was discovered in Libav 12.3.

An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c, related to offset and tag.

Published Jul 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14230: An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress.

An issue was discovered in the Viral Quiz Maker - OnionBuzz plugin before 1.2.7 for WordPress. One could exploit the id parameter in the set_count ajax nopriv handler due to there being no sanitization prior to use in a SQL query in saveQuestionVote. This allows an unauthenticated/unprivileged user to perform a SQL injection attack capable of remote code execution and information disclosure.

Published Jul 21, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14330: An issue was discovered in EspoCRM before 5.6.6.

An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create Case. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

Published Jul 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14242: An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions pr...

An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with administrator privileges can create a malicious DLL file in %SystemRoot%\System32\ that will be executed with local user privileges.

Published Jul 30, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14243: headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol...

headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin through 0.0.2 for Caddy, allows remote attackers to cause a denial of service (webserver panic and daemon crash) via a crafted HAProxy PROXY v2 request with truncated source/destination address data.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14123: Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we conside...

Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130

Published Jul 30, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14268: In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated use...

In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3. The fix was back-ported to LTS 2019.6.5 as well as LTS 2019.3.7.

Published Jul 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14331: An issue was discovered in EspoCRM before 5.6.6.

An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Create User. A malicious attacker can modify the firstName and lastName to contain JavaScript code.

Published Jul 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14284: In the Linux kernel before 5.2.3, drivers/block/floppy.c allows a denial of service by setup_format_params...

In the Linux kernel before 5.2.3, drivers/block/floppy.c allows a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PER_TRACK be zero. Next, the floppy format operation should be called. It can be triggered by an unprivileged local user even when a floppy disk has not been inserted. NOTE: QEMU creates the floppy device by default.

Published Jul 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14228: Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when r...

Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a new user at admin/includes/adminprocess.php. If there is an error when registering the user, the unsanitized username will reflect via the error page. Due to the lack of CSRF protection on the admin/includes/adminprocess.php endpoint, an attacker is able to chain the XSS with CSRF in order to cause remote exploitation.

Published Jul 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14352: In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web...

In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm_community/crm_userview_sales/_/account_new with the Account ID or Account Name field. NOTE: the vendor disputes the relevance of this finding because CSV is not the intended export format for spreadsheet applications

Published Jul 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-14289: An issue was discovered in Xpdf 4.01.01.

An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.

Published Jul 27, 2019 · Updated Aug 5, 2024