Total
10067 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-4053 | 1 Gog | 1 Galaxy | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
An exploitable local denial-of-service vulnerability exists in the privileged helper tool of GOG Galaxy's Games, version 1.2.47 for macOS. An attacker can send malicious data to the root-listening service, causing the application to terminate and become unavailable. | |||||
CVE-2019-11696 | 1 Mozilla | 1 Firefox | 2024-02-04 | 6.8 MEDIUM | 7.8 HIGH |
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67. | |||||
CVE-2019-0635 | 1 Microsoft | 7 Windows 10, Windows 7, Windows 8.1 and 4 more | 2024-02-04 | 5.5 MEDIUM | 6.2 MEDIUM |
An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validate input from an authenticated user on a guest operating system, aka 'Windows Hyper-V Information Disclosure Vulnerability'. | |||||
CVE-2017-18405 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345). | |||||
CVE-2018-15747 | 1 Glot | 1 Glot-www | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system within a "python" "files" "content" JSON file. | |||||
CVE-2019-1805 | 1 Cisco | 1 Wireless Lan Controller Software | 2024-02-04 | 3.3 LOW | 4.3 MEDIUM |
A vulnerability in certain access control mechanisms for the Secure Shell (SSH) server implementation for Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to access a CLI instance on an affected device. The vulnerability is due to a lack of proper input- and validation-checking mechanisms for inbound SSH connections on an affected device. An attacker could exploit this vulnerability by attempting to establish an SSH connection to an affected controller. An exploit could allow the attacker to access an affected device's CLI to potentially cause further attacks. This vulnerability has been fixed in version 8.5(140.0). | |||||
CVE-2018-15738 | 1 Stopzilla | 1 Antimalware | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000205F. | |||||
CVE-2019-11114 | 1 Intel | 1 Driver \& Support Assistant | 2024-02-04 | 2.1 LOW | 4.4 MEDIUM |
Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access. | |||||
CVE-2019-1587 | 1 Cisco | 28 Nexus 9000, Nexus 92160yc-x, Nexus 92300yc and 25 more | 2024-02-04 | 4.0 MEDIUM | 4.3 MEDIUM |
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information. The vulnerability occurs because the affected software does not properly validate user-supplied input. An attacker could exploit this vulnerability by issuing certain commands with filtered query results on the device. This action may cause returned messages to display confidential system information. A successful exploit could allow the attacker to read sensitive information on the device. | |||||
CVE-2018-20860 | 2 Openmpt, Opensuse | 2 Libopenmpt, Leap | 2024-02-04 | 4.3 MEDIUM | 6.5 MEDIUM |
libopenmpt before 0.3.13 allows a crash with malformed MED files. | |||||
CVE-2019-1010152 | 1 Zzcms | 1 Zzcms | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
zzcms 8.3 and earlier is affected by: File Delete to Code Execution. The impact is: getshell. The component is: user/manage.php line 31-80. | |||||
CVE-2019-9917 | 3 Canonical, Fedoraproject, Znc | 3 Ubuntu Linux, Fedora, Znc | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding. | |||||
CVE-2019-1072 | 1 Microsoft | 2 Azure Devops Server, Team Foundation Server | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'. | |||||
CVE-2019-13269 | 1 Edimax | 2 Br-6208ac V1, Br-6208ac V1 Firmware | 2024-02-04 | 5.8 MEDIUM | 8.8 HIGH |
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. A DHCP Request is sent to the router with a certain Transaction ID field. Following the DHCP protocol, the router responds with an ACK or NAK message. Studying the NAK case revealed that the router erroneously sends the NAK to both Host and Guest networks with the same Transaction ID as found in the DHCP Request. This allows encoding of data to be sent cross-router into the 32-bit Transaction ID field. | |||||
CVE-2019-5530 | 1 Bitrock | 1 Installbuilder | 2024-02-04 | 6.8 MEDIUM | 7.8 HIGH |
Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they contain a valid Authenticode signature. | |||||
CVE-2018-4400 | 1 Apple | 3 Iphone Os, Mac Os X, Watchos | 2024-02-04 | 4.3 MEDIUM | 5.5 MEDIUM |
A validation issue was addressed with improved logic. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, watchOS 5.1. | |||||
CVE-2017-18415 | 1 Cpanel | 1 Cpanel | 2024-02-04 | 4.6 MEDIUM | 7.8 HIGH |
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302). | |||||
CVE-2019-9453 | 2 Canonical, Google | 2 Ubuntu Linux, Android | 2024-02-04 | 2.1 LOW | 4.4 MEDIUM |
In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation. | |||||
CVE-2019-10672 | 1 Symonics | 1 Libmysofa | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions. | |||||
CVE-2019-1296 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2024-02-04 | 6.5 MEDIUM | 8.8 HIGH |
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295. |