Unknown · CVSS Not scored
Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.
Published Sep 29, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?n=product&c=product_admin&a=dopara&app_type=shop id parameter.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).
Published Sep 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related to mishandling of exceptions during deserialization of note plaintexts. This affects anyone who has disclosed their zaddr to a third party.
Published Sep 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
kkcms 1.3 has jx.php?url= XSS.
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initialize the resp data structure, which might allow attackers to obtain sensitive information from kernel stack memory, aka CID-df7e40425813.
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device/getNumByStatus URI.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac parameters are displayed without sanitization.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing configuration options. They are internal backend config options and person having rights to change them already has full access
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should be checking for ../ instead.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfoThreadBase::GetNICInfo+0x0000000000512918.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The Nulock application 1.5.0 for mobile devices sends a cleartext password over Bluetooth, which allows remote attackers (after sniffing the network) to take control of the lock.
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.
Published Sep 28, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter directly without sanitization (e.g., a basename call) for a pathname to file_get_contents or file_put_contents.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877.
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
Published Sep 27, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
Published Sep 25, 2019 · Updated Aug 5, 2024
Medium · CVSS 4.6
Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `Cargo.toml` is ignored in Rust 1.25.0 and prior. When Rust 1.25.0 and prior is used Cargo may download the wrong dependency, which could be squatted on crates.io to be a malicious package. This not only affects manifests that you write locally yourself, but also manifests published to crates.io. Rust 1.0.0 through Rust 1.25.0 is affected by this advisory because Cargo will ignore the `package` key in manifests. Rust 1.26.0 through Rust 1.30.0 are not affected and typically will emit an error because the `package` key is unstable. Rust 1.31.0 and after are not affected because Cargo understands the `package` key. Users of the affected versions are strongly encouraged to update their compiler to the latest available one. Preventing this issue from happening requires updating your compiler to be either Rust 1.26.0 or newer. There will be no point release for Rust versions prior to 1.26.0. Users of Rust 1.19.0 to Rust 1.25.0 can instead apply linked patches to mitigate the issue.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.cache files in /var/run/beaker/container_file/ are created when providing a valid length payload of 249 characters or fewer to the beaker.session.id cookie in a GET header. The attacker can use a long series of unique session IDs.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x0000000000000000 called from ntdll!RtlRaiseStatus+0x00000000000000b4.
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
Published Sep 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x000000000001dcfc.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the string-interner crate before 0.7.1 for Rust. It allows attackers to read from memory locations associated with dangling pointers, because of a cloning flaw.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request with directory traversal sequences in the bak[] parameter.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the portaudio-rs crate through 0.3.1 for Rust. There is a use-after-free with resultant arbitrary code execution because of a lack of unwind safety in stream_callback and stream_finished_callback.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements method.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
Published Sep 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
Published Sep 24, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
eBrigade before 5.0 has evenements.php cid SQL Injection.
Published Sep 30, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
Published Sep 24, 2019 · Updated Aug 5, 2024