Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2019
Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
CVSS Score
7.5
EPSS Score
0.002
Published
2019-08-26
DianoxDragon Hawn before 2019-07-10 allows SQL injection.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-08-26
The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-08-26
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.
CVSS Score
8.1
EPSS Score
0.003
Published
2019-08-26
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by altering the PATH variable to point to a user controlled location. When a crash is induced the trojan gdb command is executed. IBM X-Force ID: 163488.
CVSS Score
8.4
EPSS Score
0.0
Published
2019-08-26
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context. This results in arbitrary code being executed with root authority. IBM X-Force ID: 163489.
CVSS Score
8.4
EPSS Score
0.0
Published
2019-08-26
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 164555.
CVSS Score
8.2
EPSS Score
0.004
Published
2019-08-26
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts with the current capacity.
CVSS Score
9.8
EPSS Score
0.004
Published
2019-08-26
An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.017
Published
2019-08-26
An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninitialized memory.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-08-26


Contact Us

Shodan ® - All rights reserved