Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In July 2019
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\. The DACL on this folder allows any user to overwrite contents of files in this folder, resulting in Elevation of Privilege.
CVSS Score
5.5
EPSS Score
0.0
Published
2019-07-09
The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain set of inputs can be made to return any input, which can be dangerous depending on how applications use it. If an application treats arbitrary variants as trusted, this can lead to a variety of potential vulnerabilities like SQL injection or cross-site scripting (XSS).
CVSS Score
5.3
EPSS Score
0.003
Published
2019-07-09
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.
CVSS Score
7.5
EPSS Score
0.004
Published
2019-07-09
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-07-09
Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-07-09
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-09
Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-07-09
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-07-09
ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
CVSS Score
6.5
EPSS Score
0.004
Published
2019-07-09
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
CVSS Score
9.8
EPSS Score
0.126
Published
2019-07-09


Contact Us

Shodan ® - All rights reserved