Unknown · CVSS Not scored
ACDSee Free 1.1.21 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x0000000000002450.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Info-ZIP UnZip 6.0 mishandles the overlapping of files inside a ZIP container, leading to denial of service (resource consumption), aka a "better zip bomb" issue.
Published Jul 4, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.
Published Jul 3, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading. This affects WavesSysSvc64.exe 1.9.29.0.
Published Jul 3, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication). The command injection exists in the key ip_addr.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.
Published Jul 7, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass.
Published Jul 3, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.
Published Jul 3, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 through v2.1.x. This allows an attacker to insert JavaScript or HTML into the patch detail page via an email sent to a mailing list consumed by Patchwork. This affects the function msgid in templatetags/patch.py. Patchwork versions v2.1.4 and v2.0.4 will contain the fix.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to crash Asterisk when handling an SDP answer to an outgoing T.38 re-invite. To exploit this vulnerability an attacker must cause the chan_sip module to send a T.38 re-invite request to them. Upon receipt, the attacker must send an SDP answer containing both a T.38 UDPTL stream and another media stream containing only a codec (which is not permitted according to the chan_sip configuration).
Published Jul 12, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the key passwd in Routing RIP Settings.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
verification.py in django-rest-registration (aka Django REST Registration library) before 0.5.0 relies on a static string for signatures (i.e., the Django Signing API is misused), which allows remote attackers to spoof the verification process. This occurs because incorrect code refactoring led to calling a security-critical function with an incorrect argument.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the IP Address in Add Virtual Server.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the IP Address in Add Gaming Rule.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the Private Port in Add Virtual Server.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the TCP Ports To Open in Add Gaming Rule.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the UDP Ports To Open in Add Gaming Rule.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the action set_sta_enrollee_pin_5g and the key wps_sta_enrollee_pin.
Published Jul 2, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
Published Jul 3, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitrary commands via NRPE.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated.
Published Jul 29, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privileged attacker to embed malicious JavaScript in the SNMP trap receivers form. Upon visiting the /agent/action_recipient Event Action/Recipient page, the embedded code will be executed in the browser of the victim.
Published Jul 9, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled, may cause a stack overflow and overwrite the stack with arbitrary data, due to a buffer overflow in the library. Users running public servers with the above configuration are highly encouraged to upgrade as soon as possible, as there are no known mitigations.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
Published Jul 5, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js.
Published Jul 1, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.
Published Jul 16, 2019 · Updated Aug 4, 2024
High · CVSS 8.8
CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST requests to any forms in the web application. This can be exploited by tricking an authenticated user into visiting an attacker controlled web page.
Published Jul 10, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The application API of Cat Runner Decorate Home version 2.8.0 for Android does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable. Attackers can manipulate users' score parameters exchanged between client and server.
Published Jul 22, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other authenticated users can read it in the log later. The logged data can be read using Logcat on the device. When using platforms prior to Android 4.1 (Jelly Bean), the log data is not sandboxed per application; any application installed on the device has the capability to read data logged by other applications.
Published Jul 22, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.
Published Jul 22, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_device.xml.
Published Jul 22, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TronLink Wallet 2.2.0 stores user wallet keystore in plaintext and places them in insecure storage. An attacker can read and reuse the user keystore of a valid user via /data/data/com.tronlink.wallet/shared_prefs/<wallet-name>.xml to gain unauthorized access.
Published Jul 22, 2019 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
Published Jul 16, 2019 · Updated Aug 4, 2024