Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2019
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs due to a catastrophic backtracking vulnerability in a regular expression. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which were thus vulnerable.
CVSS Score
7.5
EPSS Score
0.037
Published
2019-08-02
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large sequences of nested incomplete HTML entities.
CVSS Score
7.5
EPSS Score
0.047
Published
2019-08-02
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-08-02
A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 devices with CPU variants CP300 and CP100 (All versions < V8.01), Siemens Power Meters Series 9410 (All versions < V2.2.1), Siemens Power Meters Series 9810 (All versions). An unauthenticated attacker with network access to the device could potentially insert arbitrary code which is executed before firmware verification in the device. At the time of advisory publication no public exploitation of this security vulnerability was known.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-02
GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code.
CVSS Score
7.8
EPSS Score
0.002
Published
2019-08-02
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
CVSS Score
9.8
EPSS Score
0.021
Published
2019-08-02
IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique catalog names that could cause a denial of service. IBM X-Force ID: 160296.
CVSS Score
6.2
EPSS Score
0.0
Published
2019-08-02
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
CVSS Score
6.3
EPSS Score
0.004
Published
2019-08-02
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
CVSS Score
3.1
EPSS Score
0.002
Published
2019-08-02
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
CVSS Score
5.5
EPSS Score
0.001
Published
2019-08-02


Contact Us

Shodan ® - All rights reserved