Search Results (355821 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-7296 1 Typora 1 Typora 2024-11-21 N/A
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
CVE-2019-7295 1 Typora 1 Typora 2024-11-21 N/A
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
CVE-2019-7293 1 Apple 4 Iphone Os, Mac Os X, Tvos and 1 more 2024-11-21 5.5 Medium
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A local user may be able to read kernel memory.
CVE-2019-7292 2 Apple, Redhat 7 Icloud, Iphone Os, Itunes and 4 more 2024-11-21 6.5 Medium
A validation issue was addressed with improved logic. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may result in the disclosure of process memory.
CVE-2019-7291 1 Apple 1 Airport Base Station Firmware 2024-11-21 6.5 Medium
A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmware Update 7.8.1, AirPort Base Station Firmware Update 7.9.1. An attacker in a privileged position may be able to perform a denial of service attack.
CVE-2019-7290 1 Apple 1 Shortcuts 2024-11-21 10.0 Critical
An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sandboxed process may be able to circumvent sandbox restrictions.
CVE-2019-7289 1 Apple 1 Shortcuts 2024-11-21 5.5 Medium
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Shortcuts 2.1.3 for iOS. A local user may be able to view senstive user information.
CVE-2019-7288 1 Apple 2 Iphone Os, Mac Os X 2024-11-21 9.8 Critical
The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos .
CVE-2019-7285 2 Apple, Redhat 6 Icloud, Iphone Os, Itunes and 3 more 2024-11-21 8.8 High
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.
CVE-2019-7284 1 Apple 1 Iphone Os 2024-11-21 4.3 Medium
This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.
CVE-2019-7283 2 Debian, Netkit 2 Debian Linux, Netkit 2024-11-21 7.4 High
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111.
CVE-2019-7282 3 Debian, Fedoraproject, Netkit 3 Debian Linux, Fedora, Netkit 2024-11-21 5.9 Medium
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
CVE-2019-7281 1 Primasystems 1 Flexair 2024-11-21 8.8 High
Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may allow the attacker to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
CVE-2019-7280 1 Primasystems 1 Flexair 2024-11-21 8.8 High
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session and bypass authentication.
CVE-2019-7279 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices have Hard-coded Credentials.
CVE-2019-7278 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.
CVE-2019-7277 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure.
CVE-2019-7276 1 Optergy 2 Enterprise, Proton 2024-11-21 N/A
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
CVE-2019-7275 1 Optergy 2 Enterprise, Proton 2024-11-21 6.1 Medium
Optergy Proton/Enterprise devices allow Open Redirect.
CVE-2019-7274 1 Optergy 2 Enterprise, Proton 2024-11-21 9.8 Critical
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.