LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 9 of 31.

Unknown · CVSS Not scored

CVE-2019-1010251: Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DN...

Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010173: Jsish 2.4.84 2.0484 is affected by: Reachable Assertion.

Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fixed version is: after commit 738ead193aff380a7e3d7ffb8e11e446f76867f3.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010069: moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control.

moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of service attack via a crafted file. The component is: front.c, function txt_add. The fixed version is: after commit commit 08aef597656d065e86075f3d53fda89765845eae.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010304: Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c.

Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. The impact is: Important. The component is: ProductVariant type in GraphQL API. The attack vector is: Unauthenticated user can access the GraphQL API (which is by default publicly exposed under `/graphql/` URL) and fetch products data which may include admin-restricted shop's revenue data. The fixed version is: 2.3.1.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010161: perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control.

perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network connectivity(crafting user-controlled input to bypass authentication). The fixed version is: 0.023.

Published Jul 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010176: JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow.

JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow. The impact is: denial of service and possibly arbitrary code execution. The component is: function lit_char_to_utf8_bytes (jerry-core/lit/lit-char-helpers.c:377). The attack vector is: executing crafted javascript code. The fixed version is: after commit 505dace719aebb3308a3af223cfaa985159efae0.

Published Jul 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010263: Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control.

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector is: network connectivity. The fixed version is: after commit b98a59b42ded9f9e51b2560410106207c2152d6c.

Published Jul 17, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010169: Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read.

Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read. The impact is: denial of service. The component is: function lexer_getchar (jsiLexer.c:9). The attack vector is: executing crafted javascript code. The fixed version is: 2.4.78.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010147: Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges E...

Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.

Published Jul 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010221: LineageOS 16.0 and earlier is affected by: Incorrect Access Control.

LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` can also be set in a normal adb shell session. The component is: adb shell (patches to fix this are at https://review.lineageos.org/c/LineageOS/android_system_core/+/234800, https://review.lineageos.org/c/LineageOS/android_device_lineage_sepolicy/+/234799). The attack vector is: When adb is enabled, and an attacker has physical access, `adb shell setprop service.adb.root 1` allows restarting adb as root.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010190: mgetty prior to 1.2.1 is affected by: out-of-bounds read.

mgetty prior to 1.2.1 is affected by: out-of-bounds read. The impact is: DoS, the program may crash if the memory is not mapped. The component is: putwhitespan() in g3/pbm2g3.c. The attack vector is: Local, the victim must open a specially crafted file. The fixed version is: 1.2.1.

Published Jul 24, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010024: GNU Libc current is affected by: Mitigation bypass.

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010170: Jsish 2.4.77 2.0477 is affected by: Use After Free.

Jsish 2.4.77 2.0477 is affected by: Use After Free. The impact is: denial of service. The component is: function Jsi_ObjFree (jsiObj.c:230). The attack vector is: executing crafted javascript code. The fixed version is: 2.4.78.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010066: Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control.

Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attacker could modify model specific registers. The component is: ioctl handling. The attack vector is: An attacker could exploit a bug in ioctl interface whitelist checking, in order to write to model specific registers, normally a function reserved for the root user. The fixed version is: v1.2.0.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010094: domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF).

domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change admin password. The component is: http://127.0.0.1/settings/password/ http://127.0.0.1/admin/users/add.php http://127.0.0.1/admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010028: phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scrip...

phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attack administrators and teachers, students and more. The component is: /pro-school/index.php?student/message/send_reply/. The attack vector is: <img src=x onerror=alert(document.domain) />.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010136: ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reb...

ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote.

Published Jul 19, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010060: NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow.

NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues not covered by CVE-2018-3846, CVE-2018-3847, CVE-2018-3848, and CVE-2018-3849. One example is ftp_status in drvrnet.c mishandling a long string beginning with a '4' character.

Published Jul 16, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010155: D-Link DSL-2750U 1.11 is affected by: Authentication Bypass.

D-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE: Third parties dispute this issues as not being a vulnerability because although the wizard is accessible without authentication, it can't actually configure anything. Thus, there is no denial of service or information leakage

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010096: DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF).

DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that can change the read-only user to admin. The component is: admin/users/edit.php?uid=2. The attack vector is: After the administrator logged in, open the html page.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010025: GNU Libc current is affected by: Mitigation bypass.

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.

Published Jul 15, 2019 · Updated Aug 5, 2024

Medium · CVSS 5.4

CVE-2019-1010023: GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file.

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010017: libnmap < v0.6.3 is affected by: XML Injection.

libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafted XML payload.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010065: The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow.

The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfs_cat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesystem image.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010123: MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type.

MODX Revolution Gallery 1.7.0 is affected by: CWE-434: Unrestricted Upload of File with Dangerous Type. The impact is: Creating file with custom a filename and content. The component is: Filtering user parameters before passing them into phpthumb class. The attack vector is: web request via /assets/components/gallery/connector.php.

Published Jul 23, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010054: Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF).

Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.

Published Jul 18, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010062: PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type.

PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get webshell. The component is: data/inc/images.php line36. The attack vector is: modify the MIME TYPE on HTTP request to upload a php file. The fixed version is: after commit 09f0ab871bf633973cfd9fc4fe59d4a912397cf8.

Published Jul 16, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010038: OpenModelica OMCompiler is affected by: Buffer Overflow.

OpenModelica OMCompiler is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: OPENMODELICAHOME parameter changeable via environment variable. The attack vector is: Changing an environment variable.

Published Jul 15, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-1010008: OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS).

OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, but might potentially enable persistent XSS (user could embed mal. code). The component is: Javascript code execution in "Name", "Location", "Bio" and "Starting Page" fields in the "My Account" page. File: Lib/listjs/list.js, line 67. The attack vector is: unknown, victim must open profile page if persistent was possible.

Published Jul 15, 2019 · Updated Aug 5, 2024