LiveActive security incident?Get immediate response
CVE archive

September 2019

Browse CVE records published in September 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1419 matching CVEs · Page 5 of 29.

Unknown · CVSS Not scored

CVE-2019-17050: An issue was discovered in the Voyager package through 1.2.7 for Laravel.

An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.

Published Sep 30, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16992: The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's priva...

The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.

Published Sep 29, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16941: NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XM...

NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).

Published Sep 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16926: Flower 0.9.3 has XSS via a crafted worker name.

Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access

Published Sep 27, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16755: BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can...

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.

Published Sep 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16925: Flower 0.9.3 has XSS via the name parameter in an @app.task call.

Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access

Published Sep 27, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16910: Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RN...

Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)

Published Sep 26, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16935: The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has X...

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

Published Sep 28, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16915: An issue was discovered in pfSense through 2.4.4-p3.

An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.

Published Sep 26, 2019 · Updated Aug 5, 2024

Medium · CVSS 4.6

CVE-2019-16760: Cargo prior to Rust 1.26.0 may download the wrong dependency

Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `Cargo.toml` is ignored in Rust 1.25.0 and prior. When Rust 1.25.0 and prior is used Cargo may download the wrong dependency, which could be squatted on crates.io to be a malicious package. This not only affects manifests that you write locally yourself, but also manifests published to crates.io. Rust 1.0.0 through Rust 1.25.0 is affected by this advisory because Cargo will ignore the `package` key in manifests. Rust 1.26.0 through Rust 1.30.0 are not affected and typically will emit an error because the `package` key is unstable. Rust 1.31.0 and after are not affected because Cargo understands the `package` key. Users of the affected versions are strongly encouraged to update their compiler to the latest available one. Preventing this issue from happening requires updating your compiler to be either Rust 1.26.0 or newer. There will be no point release for Rust versions prior to 1.26.0. Users of Rust 1.19.0 to Rust 1.25.0 can instead apply linked patches to mitigate the issue.

Published Sep 30, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16889: Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption...

Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.

Published Sep 25, 2019 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2019-16725: In Joomla!

In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.

Published Sep 24, 2019 · Updated Aug 5, 2024