Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14858 1 Redhat 2 Ansible Engine, Ansible Tower 2019-10-24 2.1 LOW 5.5 MEDIUM
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub parameters are processed. As a result, data in the sub parameter fields will not be masked and will be displayed if Ansible is run with increased verbosity and present in the module invocation arguments for the task.
CVE-2018-7367 2019-10-24 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-3417. Reason: This candidate is a reservation duplicate of CVE-2019-3417. Notes: All CVE users should reference CVE-2019-3417 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2018-7368 2019-10-24 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-3418. Reason: This candidate is a reservation duplicate of CVE-2019-3418. Notes: All CVE users should reference CVE-2019-3418 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2019-6282 1 Chinamobileltd 2 Gpn2.4p21-c-cn, Gpn2.4p21-c-cn Firmware 2019-10-24 6.8 MEDIUM 8.8 HIGH
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
CVE-2019-10468 1 Jenkins 1 Kubernetes Ci 2019-10-24 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-10469 1 Jenkins 1 Kubernetes Ci 2019-10-24 4.0 MEDIUM 6.5 MEDIUM
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-17666 1 Linux 1 Linux Kernel 2019-10-24 8.3 HIGH 8.8 HIGH
rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
CVE-2019-10470 1 Jenkins 1 Kubernetes Ci 2019-10-24 4.0 MEDIUM 6.5 MEDIUM
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
CVE-2019-18219 1 Sitemagic 1 Sitemagic 2019-10-24 4.3 MEDIUM 6.1 MEDIUM
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.
CVE-2019-18220 1 Sitemagic 1 Sitemagic 2019-10-24 6.8 MEDIUM 8.8 HIGH
Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.
CVE-2019-11674 1 Microfocus 1 Netiq Self Service Password Reset 2019-10-24 4.3 MEDIUM 5.9 MEDIUM
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
CVE-2019-10472 1 Jenkins 1 Libvirt Slaves 2019-10-24 4.0 MEDIUM 6.5 MEDIUM
A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-4523 4 Ibm, Linux, Microsoft and 1 more 4 Db2 High Performance Unload Load, Linux Kernel, Windows and 1 more 2019-10-24 7.2 HIGH 7.8 HIGH
IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code on the system with root privileges. IBM X-Force ID: 165481.
CVE-2019-12967 1 Themooltipass 1 Moolticute 2019-10-24 4.3 MEDIUM 6.5 MEDIUM
Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
CVE-2017-8087 1 Avm 2 Fritz\!box 7490, Fritz\!os 2019-10-24 2.1 LOW 2.4 LOW
Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate attackers to view slices of previously transmitted packets or portions of memory via via unspecified vectors.
CVE-2019-10473 1 Jenkins 1 Libvirt Slaves 2019-10-24 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
CVE-2019-10474 1 Jenkins 1 Global Post Script 2019-10-24 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.
CVE-2019-10465 1 Jenkins 1 Deploy Weblogic 2019-10-24 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.
CVE-2019-10471 1 Jenkins 1 Libvirt Slaves 2019-10-24 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-10464 1 Jenkins 1 Deploy Weblogic 2019-10-24 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or directory with an attacker-specified path exists on the Jenkins master file system.
CVE-2019-10461 1 Jenkins 1 Dynatrace Application Monitoring 2019-10-24 2.1 LOW 7.8 HIGH
Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
CVE-2019-10460 1 Jenkins 1 Bitbucket Oauth 2019-10-24 2.1 LOW 7.8 HIGH
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
CVE-2019-10050 1 Oisf 1 Suricata 2019-10-24 5.0 MEDIUM 7.5 HIGH
A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type field and the right number for shim, an attacker can manipulate the control flow, such that the condition to leave the loop is true. After leaving the loop, the network packet has a length of 2 bytes. There is no validation of this length. Later on, the code tries to read at an empty position, leading to a crash.
CVE-2019-18203 1 Ricoh 2 Mp 501, Mp 501 Firmware 2019-10-24 4.3 MEDIUM 6.1 MEDIUM
On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn and KeyDisplay parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
CVE-2017-0176 1 Microsoft 2 Windows Server 2003, Windows Xp 2019-10-24 9.3 HIGH 8.1 HIGH
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.
CVE-2019-10476 1 Jenkins 1 Zulip 2019-10-24 2.1 LOW 7.8 HIGH
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
CVE-2015-9500 1 Exquisite Ultimate Newspaper Project 1 Exquisite Ultimate Newspaper 2019-10-24 4.3 MEDIUM 6.1 MEDIUM
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
CVE-2019-17449 1 Avira 1 Software Updater 2019-10-24 4.6 MEDIUM 6.7 MEDIUM
** DISPUTED ** Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges.
CVE-2019-10467 1 Jenkins 1 Sonar Gerrit 2019-10-24 4.0 MEDIUM 6.5 MEDIUM
Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
CVE-2015-4645 2 Fedoraproject, Squashfs Project 2 Fedora, Squashfs 2019-10-24 4.3 MEDIUM 5.5 MEDIUM
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
CVE-2015-4646 1 Squashfs Project 1 Squashfs 2019-10-24 5.0 MEDIUM 7.5 HIGH
(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
CVE-2019-13657 1 Broadcom 2 Ca Performance Management, Network Operations 2019-10-24 6.5 MEDIUM 8.8 HIGH
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.
CVE-2019-6327 1 Hp 20 Laserjet Pro M280-m281 T6b80a, Laserjet Pro M280-m281 T6b80a Firmware, Laserjet Pro M280-m281 T6b81a and 17 more 2019-10-24 7.5 HIGH 9.8 CRITICAL
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have an IPP Parser potentially vulnerable to Buffer Overflow.
CVE-2019-16975 1 Fusionpbx 1 Fusionpbx 2019-10-24 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2015-9495 1 Syndication Links Project 1 Syndication Links 2019-10-24 4.3 MEDIUM 6.1 MEDIUM
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9494 1 Indieweb Post Kinds Project 1 Indieweb Post Kinds 2019-10-24 4.3 MEDIUM 6.1 MEDIUM
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.
CVE-2015-9498 1 Wpserveur 1 Wps Hide Login 2019-10-24 6.8 MEDIUM 8.8 HIGH
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
CVE-2015-9496 1 Freshmail 1 Freshmail-newsletter 2019-10-24 6.5 MEDIUM 8.8 HIGH
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
CVE-2018-1000828 1 Frostwire 1 Frostwire 2019-10-24 6.8 MEDIUM 9.0 CRITICAL
FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.
CVE-2019-5009 1 Vtiger 1 Vtiger Crm 2019-10-24 6.5 MEDIUM 7.2 HIGH
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the uploaded file is in PNG format and has a size of 150x40. One can put PHP code into the image; PHP code can be executed using "<? ?>" tags, as demonstrated by a CompanyDetailsSave action. This bypasses the bad-file-extensions protection mechanism. It is related to actions/CompanyDetailsSave.php, actions/UpdateCompanyLogo.php, and models/CompanyDetails.php.
CVE-2018-16886 3 Etcd, Fedoraproject, Redhat 5 Etcd, Fedora, Enterprise Linux Desktop and 2 more 2019-10-24 6.8 MEDIUM 8.1 HIGH
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may authenticate as that user with any valid (trusted) client certificate in a REST API request to the gRPC-gateway.
CVE-2019-6476 1 Isc 1 Bind 2019-10-24 5.0 MEDIUM 7.5 HIGH
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
CVE-2019-16973 1 Fusionpbx 1 Fusionpbx 2019-10-23 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16979 1 Fusionpbx 1 Fusionpbx 2019-10-23 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16980 1 Fusionpbx 1 Fusionpbx 2019-10-23 6.5 MEDIUM 8.8 HIGH
In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming from the URL in an unparameterized SQL query, leading to SQL injection.
CVE-2019-16981 1 Fusionpbx 1 Fusionpbx 2019-10-23 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" variable coming from the URL, which is reflected on 2 occasions in HTML, leading to XSS.
CVE-2019-16982 1 Fusionpbx 1 Fusionpbx 2019-10-23 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16983 1 Fusionpbx 1 Fusionpbx 2019-10-23 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface), which uses an unsanitized "param" variable constructed partially from the URL args and reflected in HTML, leading to XSS.
CVE-2019-16984 1 Fusionpbx 1 Fusionpbx 2019-10-23 4.3 MEDIUM 6.1 MEDIUM
In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming from the URL, which is base64 decoded and reflected in HTML, leading to XSS.
CVE-2019-16985 1 Fusionpbx 1 Fusionpbx 2019-10-23 8.5 HIGH 6.5 MEDIUM
In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the URL, which is base64 decoded and allows deletion of any file of the system.