Base de données CVE
Archive des vulnérabilités connues (CVE) avec score CVSS, gravité, produits et éditeurs concernés. Filtrez par année et par sévérité.
- CVE-2019-15107Critique9.8
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
- CVE-2019-0344Critique9.8
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
- CVE-2019-11581Critique9.8
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.
- CVE-2019-0193Élevée7.2
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
- CVE-2019-11708Critique10.0
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.
- CVE-2019-11707Élevée8.8
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
- CVE-2019-1579Élevée8.1
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
- CVE-2019-13272Élevée7.8
Dans le noyau Linux avant 5.1.17, ptrace_link dans kernel/ptrace.c gère incorrectement l'enregistrement des credentials d'un processus qui veut créer une relation ptrace, ce qui permet à des utilisateurs locaux d'obtenir un accès root en exploitant certains scénarios avec une relation de processus parent-enfant, où un parent abandonne ses privilèges et appelle execve (permettant potentiellement un contrôle par un attaquant). Un facteur contributif est un problème de durée de vie d'objet (qui peut également provoquer un panic). Un autre facteur contributif est le marquage incorrect d'une relation ptrace comme privilégiée, qui est exploitable via (par exemple) l'utilitaire pkexec de Polkit avec PTRACE_TRACEME. NOTE : SELinux deny_ptrace pourrait être une solution de contournement utilisable dans certains environnements.
- CVE-2019-12991Élevée8.8
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
- CVE-2019-12989Critique9.8
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
- CVE-2019-1132Élevée7.8
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
- CVE-2019-1130Élevée7.8
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.
- CVE-2019-1129Élevée7.8
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
- CVE-2019-1068Élevée8.8
Une vulnérabilité d'exécution de code à distance existe dans Microsoft SQL Server lorsqu'il gère incorrectement le traitement des fonctions internes, alias 'Microsoft SQL Server Remote Code Execution Vulnerability'.
- CVE-2019-0880Élevée7.8
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
- CVE-2018-18325Élevée7.5
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
- CVE-2018-15811Élevée7.5
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
- CVE-2019-7256Critique9.8
Linear eMerge E3-Series devices allow Command Injections.
- CVE-2019-5786Moyenne6.5
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
- CVE-2019-1069Élevée7.8
An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an attacker would require unprivileged code execution on a victim system. The security update addresses the vulnerability by correctly validating file operations.
This product uses the NVD API but is not endorsed or certified by the NVD.