Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18475 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 8.8 HIGH
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
CVE-2017-18470 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 8.8 HIGH
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
CVE-2017-18415 1 Cpanel 1 Cpanel 2019-08-12 4.6 MEDIUM 7.8 HIGH
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
CVE-2017-18414 1 Cpanel 1 Cpanel 2019-08-12 5.8 MEDIUM 7.4 HIGH
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
CVE-2016-10860 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
CVE-2016-10833 1 Cpanel 1 Cpanel 2019-08-12 5.0 MEDIUM 7.5 HIGH
cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).
CVE-2016-10834 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 8.8 HIGH
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
CVE-2016-10831 1 Cpanel 1 Cpanel 2019-08-12 6.5 MEDIUM 7.2 HIGH
cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).
CVE-2016-10830 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 8.1 HIGH
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
CVE-2017-18413 1 Cpanel 1 Cpanel 2019-08-12 4.6 MEDIUM 7.8 HIGH
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
CVE-2016-10825 1 Cpanel 1 Cpanel 2019-08-12 5.5 MEDIUM 8.1 HIGH
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
CVE-2017-18387 1 Cpanel 1 Cpanel 2019-08-12 9.0 HIGH 7.2 HIGH
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
CVE-2007-6763 1 Sas 1 Sas Drug Development 2019-08-12 6.5 MEDIUM 8.8 HIGH
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.
CVE-2019-14296 1 Upx Project 1 Upx 2019-08-11 6.8 MEDIUM 7.8 HIGH
canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impact via a crafted UPX packed file.
CVE-2019-11508 1 Pulsesecure 1 Pulse Connect Secure 2019-08-09 6.5 MEDIUM 7.2 HIGH
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.
CVE-2018-9154 1 Jasper Project 1 Jasper 2019-08-09 5.0 MEDIUM 7.5 HIGH
There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.
CVE-2017-6852 1 Jasper Project 1 Jasper 2019-08-09 6.8 MEDIUM 7.8 HIGH
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
CVE-2017-18388 1 Cpanel 1 Cpanel 2019-08-09 7.2 HIGH 7.8 HIGH
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
CVE-2016-10771 1 Cpanel 1 Cpanel 2019-08-09 5.5 MEDIUM 8.1 HIGH
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).
CVE-2016-10773 1 Cpanel 1 Cpanel 2019-08-09 6.5 MEDIUM 8.8 HIGH
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
CVE-2016-10787 1 Cpanel 1 Cpanel 2019-08-09 5.5 MEDIUM 8.1 HIGH
The Host Access Control feature in cPanel before 60.0.25 mishandles actionless host.deny entries (SEC-187).
CVE-2016-10788 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
CVE-2016-10789 1 Cpanel 1 Cpanel 2019-08-09 6.5 MEDIUM 8.8 HIGH
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
CVE-2016-10804 1 Cpanel 1 Cpanel 2019-08-09 8.7 HIGH 8.1 HIGH
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58).
CVE-2016-10802 1 Cpanel 1 Cpanel 2019-08-09 6.5 MEDIUM 8.8 HIGH
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
CVE-2016-10811 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
CVE-2016-10810 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
CVE-2016-10809 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
CVE-2016-10805 1 Cpanel 1 Cpanel 2019-08-09 6.5 MEDIUM 8.8 HIGH
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
CVE-2017-18433 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
CVE-2017-18434 1 Cpanel 1 Cpanel 2019-08-09 7.2 HIGH 7.8 HIGH
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
CVE-2017-18435 1 Cpanel 1 Cpanel 2019-08-09 7.5 HIGH 7.3 HIGH
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
CVE-2019-7911 1 Magento 1 Magento 2019-08-09 6.5 MEDIUM 7.2 HIGH
A server-side request forgery (SSRF) vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with access to the admin panel to manipulate system configuration and execute arbitrary code.
CVE-2019-7912 1 Magento 1 Magento 2019-08-09 6.5 MEDIUM 7.2 HIGH
A file upload filter bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This can be exploited by an authenticated user with admin privileges to edit configuration keys to remove file extension filters, potentially resulting in the malicious upload and execution of malicious files on the server.
CVE-2016-10845 1 Cpanel 1 Cpanel 2019-08-08 6.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
CVE-2016-10846 1 Cpanel 1 Cpanel 2019-08-08 8.5 HIGH 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
CVE-2016-10843 1 Cpanel 1 Cpanel 2019-08-08 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
CVE-2016-10837 1 Cpanel 1 Cpanel 2019-08-08 8.5 HIGH 7.5 HIGH
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
CVE-2016-10848 1 Cpanel 1 Cpanel 2019-08-08 9.0 HIGH 7.2 HIGH
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
CVE-2016-10847 1 Cpanel 1 Cpanel 2019-08-08 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
CVE-2016-0751 1 Rubyonrails 2 Rails, Ruby On Rails 2019-08-08 5.0 MEDIUM 7.5 HIGH
actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.
CVE-2015-7581 1 Rubyonrails 1 Rails 2019-08-08 5.0 MEDIUM 7.5 HIGH
actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.
CVE-2016-2098 2 Debian, Rubyonrails 3 Debian Linux, Rails, Ruby On Rails 2019-08-08 7.5 HIGH 7.3 HIGH
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-0752 1 Rubyonrails 2 Rails, Ruby On Rails 2019-08-08 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
CVE-2017-18390 1 Cpanel 1 Cpanel 2019-08-08 7.2 HIGH 7.8 HIGH
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
CVE-2016-6317 1 Rubyonrails 1 Rails 2019-08-08 5.0 MEDIUM 7.5 HIGH
Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660, CVE-2012-2694, and CVE-2013-0155.
CVE-2016-10859 1 Cpanel 1 Cpanel 2019-08-08 5.5 MEDIUM 8.1 HIGH
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
CVE-2019-7849 1 Magento 1 Magento 2019-08-08 5.0 MEDIUM 7.5 HIGH
A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. This impacts Magento 1.x prior to 1.9.4.2, Magento Commerce prior to 1.14.4.2, Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2.
CVE-2016-10750 1 Hazelcast 1 Hazelcast 2019-08-08 6.8 MEDIUM 8.1 HIGH
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.
CVE-2017-18460 1 Cpanel 1 Cpanel 2019-08-07 7.2 HIGH 7.8 HIGH
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).