Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1000547 1 Corebos 1 Corebos 2019-10-08 5.0 MEDIUM 5.3 MEDIUM
coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no permissions to. .
CVE-2019-14745 1 Radare 1 Radare2 2019-10-08 6.8 MEDIUM 7.8 HIGH
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.
CVE-2017-18552 1 Linux 1 Linux Kernel 2019-10-07 4.6 MEDIUM 7.8 HIGH
An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.
CVE-2018-10238 1 Bacnet Protocol Stack Project 1 Bacnet Protocol Stack 2019-10-07 7.5 HIGH 9.8 CRITICAL
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_encode_forwarded_npdu() which copies the content from the request into a local in the bvlc_bdt_forward_npdu() stack frame and clobbers the canary. The attack vector is: A BACnet/IP device with BBMD enabled based on this library connected to IP network. The fixed version is: 0.8.6.
CVE-2019-1010073 2019-10-07 N/A N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10238. Reason: This issue was MERGED into CVE-2018-10238 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2018-10238 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
CVE-2019-15042 1 Jetbrains 1 Teamcity 2019-10-07 5.0 MEDIUM 7.5 HIGH
An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https connections. This was fixed in TeamCity 2019.1.
CVE-2016-10907 1 Linux 1 Linux Kernel 2019-10-07 4.6 MEDIUM 7.8 HIGH
An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the function ad5755_parse_dt.
CVE-2018-7274 1 Quarx Cms Project 1 Quarx Cms 2019-10-07 4.3 MEDIUM 6.1 MEDIUM
Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name).
CVE-2019-4013 1 Ibm 1 Bigfix Platform 2019-10-07 9.0 HIGH 9.9 CRITICAL
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
CVE-2003-1331 1 Oracle 1 Mysql 2019-10-07 4.0 MEDIUM N/A
Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a different vulnerability than CVE-2001-1453.
CVE-2004-0835 3 Debian, Mysql, Oracle 3 Debian Linux, Mysql, Mysql 2019-10-07 7.5 HIGH N/A
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
CVE-2002-0969 1 Oracle 1 Mysql 2019-10-07 4.6 MEDIUM N/A
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group.
CVE-2002-1373 1 Oracle 1 Mysql 2019-10-07 5.0 MEDIUM N/A
Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative integers to be provided to a memcpy call.
CVE-2002-1374 2 Oracle, Symantec Veritas 3 Mysql, Netbackup Advanced Reporter, Netbackup Global Data Manager 2019-10-07 7.5 HIGH N/A
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.
CVE-2002-1375 2 Oracle, Symantec Veritas 3 Mysql, Netbackup Advanced Reporter, Netbackup Global Data Manager 2019-10-07 7.5 HIGH N/A
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
CVE-2002-1376 2 Oracle, Symantec Veritas 3 Mysql, Netbackup Advanced Reporter, Netbackup Global Data Manager 2019-10-07 7.5 HIGH N/A
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
CVE-2003-0073 1 Oracle 1 Mysql 2019-10-07 5.0 MEDIUM N/A
Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.
CVE-2003-0150 1 Oracle 1 Mysql 2019-10-07 9.0 HIGH N/A
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.
CVE-2001-0407 1 Oracle 1 Mysql 2019-10-07 4.6 MEDIUM N/A
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
CVE-2001-1453 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter.
CVE-2001-1454 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request.
CVE-2002-1809 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL database.
CVE-2002-1921 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database.
CVE-2002-1923 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection.
CVE-2000-0148 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
CVE-2001-1274 1 Oracle 1 Mysql 2019-10-07 7.5 HIGH N/A
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
CVE-2001-1275 1 Oracle 1 Mysql 2019-10-07 7.2 HIGH N/A
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
CVE-1999-1188 1 Oracle 1 Mysql 2019-10-07 4.6 MEDIUM N/A
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
CVE-2000-0045 1 Oracle 1 Mysql 2019-10-07 6.4 MEDIUM N/A
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
CVE-2000-0981 1 Oracle 1 Mysql 2019-10-07 7.2 HIGH N/A
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
CVE-2001-1255 2 Mysql, Oracle 2 Winmysqladmin, Mysql 2019-10-07 4.6 MEDIUM N/A
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
CVE-2019-17040 1 Rsyslog 1 Rsyslog 2019-10-07 7.5 HIGH 9.8 CRITICAL
contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
CVE-2019-8291 1 Online Store System Project 1 Online Store System 2019-10-07 6.4 MEDIUM 7.5 HIGH
Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for path traversal.
CVE-2019-17074 1 Xunruicms 1 Xunruicms 2019-10-07 3.5 LOW 5.4 MEDIUM
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
CVE-2019-9377 1 Google 1 Android 2019-10-07 2.1 LOW 3.3 LOW
In FingerprintService, there is a possible bypass for operating system protections that isolate user profiles from each other due to a missing permission check. This could lead to a local information disclosure of metadata about the biometrics of another user on the device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-128599663
CVE-2018-13699 1 Destineedtoken Project 1 Destineedtoken 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for DestiNeed (DSN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13670 1 Gfcoin 1 Gfcb 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for GFCB, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2019-9312 1 Google 1 Android 2019-10-07 2.1 LOW 5.5 MEDIUM
In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-78288018
CVE-2019-9356 1 Google 1 Android 2019-10-07 1.9 LOW 5.0 MEDIUM
In NFC server, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111699773
CVE-2019-9246 1 Google 1 Android 2019-10-07 1.9 LOW 5.0 MEDIUM
In NFC, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-120428637
CVE-2018-13169 1 Ethereum Cash Pro Coin Project 1 Ethereum Cash Pro Coin 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for Ethereum Cash Pro (ECP), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13170 1 Snoqualmiecoin Project 1 Snoqualmiecoin 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for Snoqualmie Coin (SNOW), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13181 1 Cointroops Project 1 Cointroops 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for Troo, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13176 1 Trustzen Project 1 Trustzen 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for Trust Zen Token (ZEN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13177 1 Miningrigrentalstoken Project 1 Miningrigrentalstoken 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for MiningRigRentals Token (MRR), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13179 1 Aircontacttoken Project 1 Aircontacttoken 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for Air-Contact Token (AIR), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13180 1 Immcoin Project 1 Immcoin 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for IMM Coin (IMC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13194 1 Ttcoin Project 1 Ttcoin 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for TongTong Coin (TTCoin), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13183 1 Jwctoken Project 1 Jwctoken 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for JWC, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CVE-2018-13195 1 Cranooadvanced Project 1 Cranooadvanced 2019-10-07 5.0 MEDIUM 7.5 HIGH
The mintToken function of a smart contract implementation for Cranoo (CRN), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.