Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2019-20202

Published Dec 31, 2019

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block that was not allocated, leading to an invalid free and segm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20201

Published Dec 31, 2019

An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an infinite loop in which memory allocations occur.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20200

Published Dec 31, 2019

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling, leading to a heap-based buff…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20199

Published Dec 31, 2019

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dere…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20198

Published Dec 31, 2019

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack consumption for a crafted XML file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5595

Published Dec 31, 2019

Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cau…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5593

Published Dec 31, 2019

The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrappin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5592

Published Dec 31, 2019

Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5591

Published Dec 31, 2019

SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7071

Published Dec 31, 2019

Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HT…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7070

Published Dec 31, 2019

The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3585

Published Dec 31, 2019

Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal duri…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2776

Published Dec 31, 2019

go.cgi in GoScript 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) query string or (2) artarchive parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20197

Published Dec 31, 2019

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-se…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14466

Published Dec 31, 2019

The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9668

Published Dec 31, 2019

An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote attackers to cause a denial of service (daemon crash) via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9554

Published Dec 31, 2019

In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9553

Published Dec 31, 2019

Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 17,305 CVEsPage 1 of 693