LiveActive security incident?Get immediate response
CVE archive

August 2019

Browse CVE records published in August 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1365 matching CVEs · Page 5 of 28.

High · CVSS 7.4

CVE-2019-11060: HG100 contains an Uncontrolled Resource Consumption vulnerability

The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a long period of time. CVSS 3.0 Base score 7.4 (Availability impacts). CVSS vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).

Published Aug 29, 2019 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2019-3744: Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability.

Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software package feature with a race condition and a path traversal exploit in order to run a malicious executable with elevated privileges.

Published Aug 9, 2019 · Updated Sep 16, 2024

Medium · CVSS 6.3

CVE-2019-11850: ALEOS AT Command Stack Overflow

A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow code execution

Published Aug 21, 2020 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2019-9850: Insufficient url validation allowing LibreLogo script execution

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from script event handers. However an insufficient url validation vulnerability in LibreOffice allowed malicious to bypass that protection and again trigger calling LibreLogo from script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

Published Aug 15, 2019 · Updated Sep 16, 2024

High · CVSS 7.1

CVE-2019-3717: Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability.

Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attacker with physical access to the system could potentially bypass intended Secure Boot restrictions to run unsigned and untrusted code on expansion cards installed in the system during platform boot. Refer to https://www.dell.com/support/article/us/en/04/sln317683/dsa-2019-043-dell-client-improper-access-control-vulnerability?lang=en for versions affected by this vulnerability.

Published Aug 5, 2019 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2019-5633: Hickory Smart Lock Insecure Storage on iOS

An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwith Products, LLC. The application's database was found to contain information that could be used to control the lock devices remotely. This issue affects Hickory Smart for iOS, version 01.01.07 and prior versions.

Published Aug 22, 2019 · Updated Sep 16, 2024

Medium · CVSS 6.7

CVE-2019-4536: IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with...

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the restored system. IBM X-Force ID: 165592.

Published Aug 29, 2019 · Updated Sep 16, 2024

Low · CVSS 3.7

CVE-2019-4688: IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization toke...

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 171825.

Published Aug 26, 2020 · Updated Sep 16, 2024

Medium · CVSS 5.4

CVE-2019-11276: Apps Manager sends tokens to Spring apps via HTTP

Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent requests via unsecured http. An adjacent unauthenticated user could eavesdrop on the network traffic and gain access to the unencrypted token allowing the attacker to read the type of access a user has over an app. They may also modify the logging level, potentially leading to lost information that would otherwise have been logged.

Published Aug 19, 2019 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2019-20151: An XSS issue was discovered in TreasuryXpress 19191105.

An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed by the application's administrator(s). A malicious payload can be injected within the Multi Approval security component and inserted via the Note field. As a result, the payload is executed by the application's administrator(s).

Published Aug 20, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-20150: In TreasuryXpress 19191105, a logged-in user can discover saved credentials, even though the UI hides them.

In TreasuryXpress 19191105, a logged-in user can discover saved credentials, even though the UI hides them. Using functionality within the application and a malicious host, it is possible to force the application to expose saved SSH/SFTP credentials. This can be done by using the application's editor to change the expected SFTP Host IP to a malicious host, and then using the Check Connectivity option. The application then sends these saved credentials to the malicious host.

Published Aug 20, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-20152: An XSS issue was discovered in TreasuryXpress 19191105.

An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, malicious JavaScript can be executed throughout the application. A malicious payload can be injected within the Custom Workflow component and inserted via the Create New Workflow field. As a result, the payload is executed via the navigation bar throughout the application.

Published Aug 20, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19455: Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate p...

Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands in any file and execute them as root. This issue was resolved in Wowza Streaming Engine 4.8.5.

Published Aug 3, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-19453: Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2).

Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine 4.8.5.

Published Aug 3, 2020 · Updated Aug 5, 2024