CVE Schwachstellen
CVE-Datenbank angereichert mit CISA KEV und NVD Daten
| CVE ID | CVSS | Schweregrad | KEV | Sichtungen |
|---|---|---|---|---|
| CVE-2019-13655 Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a small JPEG file to specify dimensions of 64250x64250 pixels, which is mishandled ... | N/A | NONE | — | 0 |
| CVE-2019-14415 An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vulnerability allows a malicious VRP user to inject malicious script into another u... | 4.8 | MEDIUM | — | 0 |
| CVE-2019-14416 An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the... | 7.2 | HIGH | — | 0 |
| CVE-2019-14417 An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the... | N/A | NONE | — | 0 |
| CVE-2019-14418 An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to o... | 8.8 | HIGH | — | 0 |
| CVE-2019-14431 In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseS... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-14439 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally ex... | 7.5 | HIGH | — | 0 |
| CVE-2015-9290 In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of cur and limit are sensible before going to Again. | N/A | NONE | — | 0 |
| CVE-2017-18380 edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name. | 7.5 | HIGH | — | 0 |
| CVE-2019-13635 The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversal. | N/A | NONE | — | 0 |
| CVE-2019-14327 A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the plugin settings. | N/A | NONE | — | 0 |
| CVE-2019-14381 libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument to an empty instrument note map slot. | N/A | NONE | — | 0 |
| CVE-2019-14442 In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang, with 100% CPU consumption. Attackers could leverage this vulnerability to caus... | 6.5 | MEDIUM | — | 0 |
| CVE-2019-14443 An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote attackers to cause a denial of service (application crash), as demonstrated by avc... | 6.5 | MEDIUM | — | 0 |
| CVE-2019-14444 apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF ... | 5.5 | MEDIUM | — | 0 |
| CVE-2018-20867 cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). | N/A | NONE | — | 0 |
| CVE-2019-11775 All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that ... | 7.4 | HIGH | — | 0 |
| CVE-2019-14392 cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501). | N/A | NONE | — | 0 |
| CVE-2019-4062 IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to e... | 7.1 | HIGH | — | 0 |
| CVE-2019-4285 IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attack... | 5.4 | MEDIUM | — | 0 |
| CVE-2019-4456 IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera... | 7.1 | HIGH | — | 0 |
| CVE-2018-20862 cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). | N/A | NONE | — | 0 |
| CVE-2018-20863 cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | N/A | NONE | — | 0 |
| CVE-2018-20864 cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | N/A | NONE | — | 0 |
| CVE-2018-20865 cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). | N/A | NONE | — | 0 |
| CVE-2018-20866 cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | N/A | NONE | — | 0 |
| CVE-2018-16871 A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null poi... | 7.5 | HIGH | — | 0 |
| CVE-2019-10129 A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default config... | 6.5 | MEDIUM | — | 0 |
| CVE-2019-10130 A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statist... | 4.3 | MEDIUM | — | 0 |
| CVE-2019-10138 A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authe... | 8.8 | HIGH | — | 0 |
| CVE-2019-10141 A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.... | N/A | NONE | — | 0 |
| CVE-2018-20872 DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649. | N/A | NONE | — | 0 |
| CVE-2019-10142 A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in ... | N/A | NONE | — | 0 |
| CVE-2019-11202 An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, and v2.2.0 through 2.2.1. When Rancher starts for the first time, it creates a de... | N/A | NONE | — | 0 |
| CVE-2019-14318 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operat... | N/A | NONE | — | 0 |
| CVE-2019-1552 OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDI... | N/A | NONE | — | 0 |
| CVE-2019-14242 An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefen... | N/A | NONE | — | 0 |
| CVE-2019-14313 A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL... | 9.8 | CRITICAL | — | 0 |
| CVE-2017-18381 The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials. | 7.2 | HIGH | — | 0 |
| CVE-2018-20859 edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. | 6.1 | MEDIUM | — | 0 |
| CVE-2018-20860 libopenmpt before 0.3.13 allows a crash with malformed MED files. | 6.5 | MEDIUM | — | 0 |
| CVE-2018-20861 libopenmpt before 0.3.11 allows a crash with certain malformed custom tunings in MPTM files. | N/A | NONE | — | 0 |
| CVE-2018-20871 In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890). | N/A | NONE | — | 0 |
| CVE-2019-14380 libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files. | 6.5 | MEDIUM | — | 0 |
| CVE-2019-14382 DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. | 6.5 | MEDIUM | — | 0 |
| CVE-2019-14383 J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. | 6.5 | MEDIUM | — | 0 |
| CVE-2019-13026 OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the data... | N/A | NONE | — | 0 |
| CVE-2019-5448 Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network. | 8.1 | HIGH | — | 0 |
| CVE-2019-5449 A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. | 4.3 | MEDIUM | — | 0 |
| CVE-2019-5453 Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. | 6.1 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.