LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 16 of 31.

Unknown · CVSS Not scored

CVE-2019-13447: An issue was discovered in Sertek Xpare 3.67.

An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious agent could access the backend database via SQL injection.

Published Jul 17, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13404: The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes i...

The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x

Published Jul 8, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13351: posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and l...

posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.

Published Jul 5, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13287: In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() l...

In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool. It might allow an attacker to cause Information Disclosure. This is related to CVE-2018-16368.

Published Jul 4, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13382: UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in...

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

Published Jul 26, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13292: A SQL Injection issue was discovered in webERP 4.15.

A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is decoded, it is deserialized. Then, this deserialized data goes directly into a SQL query, with no sanitizing checks.

Published Jul 4, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13278: TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when pro...

TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup wizard, allowing an unauthenticated user to run arbitrary commands on the device. The vulnerability can be exercised on the local intranet or remotely if remote administration is enabled.

Published Jul 10, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-13344: An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress all...

An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthenticated attackers to change settings. The contains() function in wp_like_button.php did not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update settings, as demonstrated by the wp-admin/admin.php?page=facebook-like-button each_page_url or code_snippet parameter.

Published Jul 5, 2019 · Updated Aug 4, 2024