LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 8 of 31.

Unknown · CVSS Not scored

CVE-2019-1010306: Slanger 0.6.0 is affected by: Remote Code Execution (RCE).

Slanger 0.6.0 is affected by: Remote Code Execution (RCE). The impact is: A remote attacker can execute arbitrary commands by sending a crafted request to the server. The component is: Message handler & request validator. The attack vector is: Remote unauthenticated. The fixed version is: after commit 5267b455caeb2e055cccf0d2b6a22727c111f5c3.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010275: helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation.

helm Before 2.7.2 is affected by: CWE-295: Improper Certificate Validation. The impact is: Unauthorized clients could connect to the server because self-signed client certs were aloowed. The component is: helm (many files updated, see https://github.com/helm/helm/pull/3152/files/1096813bf9a425e2aa4ac755b6c991b626dfab50). The attack vector is: A malicious client could connect to the server over the network. The fixed version is: 2.7.2.

Published Jul 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010245: The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation.

The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java. The attack vector is: network connectivity. The fixed version is: 1.15.

Published Jul 19, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010290: Babel: Multilingual site Babel All is affected by: Open Redirection.

Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.

Published Jul 16, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010315: WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero.

WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (dsdiff.c:282). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/4c0faba32fddbd0745cbfaf1e1aeb3da5d35b9fc.

Published Jul 11, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010172: Jsish 2.4.84 2.0484 is affected by: Uncontrolled Resource Consumption.

Jsish 2.4.84 2.0484 is affected by: Uncontrolled Resource Consumption. The impact is: denial of service. The component is: function jsiValueGetString (jsiUtils.c). The attack vector is: executing crafted javascript code. The fixed version is: after commit f3a8096e0ce44bbf36c1dcb6e603adf9c8670c39.

Published Jul 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010171: Jsish 2.4.83 2.0483 is affected by: Nullpointer dereference.

Jsish 2.4.83 2.0483 is affected by: Nullpointer dereference. The impact is: denial of service. The component is: function jsi_DumpFunctions (jsiEval.c:567). The attack vector is: executing crafted javascript code. The fixed version is: 2.4.84.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010246: MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database...

MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. The impact is: MySQL database content disclosure (e.g. username, password). The component is: The API call in the function allowAction() in NewslettersController.php. The attack vector is: HTTP Get request. The fixed version is: c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010204: GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation,...

GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010179: PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of S...

PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: It is possible to manipulate gpg-keys or execute commands remotely. The component is: function pgp_exec() phkp.php:98. The attack vector is: HKP-Api: /pks/lookup?search.

Published Jul 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010201: Jeesite 1.2.7 is affected by: SQL Injection.

Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() function in src/main/java/com.thinkgem.jeesite/modules/act/ActDao.java has SQL Injection vulnerability. The attack vector is: network connectivity,authenticated. The fixed version is: 4.0 and later.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010301: jhead 3.03 is affected by: Buffer Overflow.

jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010199: ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS).

ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is reflected in the server response, hence executed by the browser. The component is: the query used in the GET request is prone. The attack vector is: Since there is no server-side validation and If Browser encoding is bypassed, the victim is affected when opening a crafted URL. The fixed version is: 5.2.0.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010174: CImg The CImg Library v.2.3.3 and earlier is affected by: command injection.

CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.

Published Jul 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010287: Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS).

Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious url.

Published Jul 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010191: marginalia < 1.6 is affected by: SQL Injection.

marginalia < 1.6 is affected by: SQL Injection. The impact is: The impact is a injection of any SQL queries when a user controller argument is added as a component. The component is: Affects users that add a component that is user controller, for instance a parameter or a header. The attack vector is: Hacker inputs a SQL to a vulnerable vector(header, http parameter, etc). The fixed version is: 1.6.

Published Jul 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010218: Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer...

Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee command. The attack vector is: Overwrite argv[0] to an insane length with execl. The fixed version is: There's no fix yet.

Published Jul 22, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010299: The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure.

The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait implementation for std::collections::vec_deque::Iter. The attack vector is: The program needs to invoke debug printing for iterator over an empty VecDeque. The fixed version is: 1.30.0, nightly versions after commit b85e4cc8fadaabd41da5b9645c08c68b8f89908d.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010228: OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow.

OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress() (file dcrledec.h, line 122). The attack vector is: Many scenarios of DICOM file processing (e.g. DICOM to image conversion). The fixed version is: 3.6.4, after commit 40917614e.

Published Jul 22, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010207: Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS).

Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010305: libmspack 0.9.1alpha is affected by: Buffer Overflow.

libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm file. The fixed version is: after commit 2f084136cfe0d05e5bf5703f3e83c6d955234b4d.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010202: Jeesite 1.2.7 is affected by: XML External Entity (XXE).

Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function in src/main/java/com.thinkgem.jeesite/modules/act/service/ActProcessService.java. The attack vector is: network connectivity,authenticated,must upload a specially crafted xml file. The fixed version is: 4.0 and later.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010205: LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal.

LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here: https://lgtm.com/projects/g/linagora/hublin/snapshot/af9f1ce253b4ee923ff8da8f9d908d02a8e95b7f/files/backend/webserver/views.js?sort=name&dir=ASC&mode=heatmap&showExcluded=false#xb24eb0101d2aec21:1. The attack vector is: Attacker sends a specially crafted HTTP request.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010178: Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.

Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The attack vector is: Uploading a PHP file or change data in the database. The fixed version is: https://github.com/modxcms/fred/commit/139cefac83b2ead90da23187d92739dec79d3ccd and https://github.com/modxcms/fred/commit/01f0a3d1ae7f3970639c2a0db1887beba0065246.

Published Jul 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010237: Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stor...

Ilias 5.3 before 5.3.12; 5.2 before 5.2.21 is affected by: Cross Site Scripting (XSS) - CWE-79 Type 2: Stored XSS (or Persistent). The impact is: Execute code in the victim's browser. The component is: Assessment / TestQuestionPool. The attack vector is: Cloze Test Text gap (attacker) / Corrections view (victim). The fixed version is: 5.3.12.

Published Jul 22, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010249: The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow.

The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is: network management and connectivity.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010220: tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read.

tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c". The attack vector is: The victim must open a specially crafted pcap file.

Published Jul 22, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010189: mgetty prior to version 1.2.1 is affected by: Infinite Loop.

mgetty prior to version 1.2.1 is affected by: Infinite Loop. The impact is: DoS, the program does never terminates. The component is: g3/g32pbm.c. The attack vector is: Local, the user should open a specially crafted file. The fixed version is: 1.2.1.

Published Jul 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010177: Jsish 2.4.70 2.047 is affected by: Use After Free.

Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c:39). The attack vector is: executing crafted javascript code. The fixed version is: after commit 48a66c798d.

Published Jul 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010200: Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580...

Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). The impact is: Remote code execution with the same privileges as the servers. The component is: Two web servers in the projects expose three vulnerable endpoints that can be accessed remotely. The endpoints are defined at: - /tts: https://github.com/google/voice-builder/blob/3a449a3e8d5100ff323161c89b897f6d5ccdb6f9/merlin_model_server/api.js#L34 - /alignment: https://github.com/google/voice-builder/blob/3a449a3e8d5100ff323161c89b897f6d5ccdb6f9/festival_model_server/api.js#L28 - /tts: https://github.com/google/voice-builder/blob/3a449a3e8d5100ff323161c89b897f6d5ccdb6f9/festival_model_server/api.js#L65. The attack vector is: Attacker sends a GET request to the vulnerable endpoint with a specially formatted query parameter. The fixed version is: After commit f6660e6d8f0d1d931359d591dbdec580fef36d36.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010307: GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS).

GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and click on the "Link Tickets" feature, 3- a request to the endpoint fetches js and executes it.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010057: nfdump 1.6.16 and earlier is affected by: Buffer Overflow.

nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a specially crafted file. The fixed version is: after commit 9f0fe9563366f62a71d34c92229da3432ec5cf0e.

Published Jul 16, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010252: The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation.

The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management and connectivity.

Published Jul 18, 2019 · Updated Aug 5, 2024