Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In June 2019
A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution.
CVSS Score
7.8
EPSS Score
0.007
Published
2019-06-07
A use after free in the TextBox field Mouse Enter action in IReader_ContentProvider can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031. An attacker can leverage this to gain remote code execution. Relative to CVE-2018-19444, this has a different free location and requires different JavaScript code for exploitation.
CVSS Score
7.8
EPSS Score
0.005
Published
2019-06-07
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
CVSS Score
4.8
EPSS Score
0.003
Published
2019-06-07
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
CVSS Score
7.2
EPSS Score
0.003
Published
2019-06-07
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-06-07
aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.
CVSS Score
9.8
EPSS Score
0.008
Published
2019-06-07
aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.
CVSS Score
7.5
EPSS Score
0.006
Published
2019-06-07
aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.
CVSS Score
7.5
EPSS Score
0.011
Published
2019-06-07
Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.
CVSS Score
8.8
EPSS Score
0.008
Published
2019-06-07
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.
CVSS Score
7.8
EPSS Score
0.001
Published
2019-06-07


Contact Us

Shodan ® - All rights reserved