Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2019
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
CVSS Score
6.1
EPSS Score
0.003
Published
2019-10-09
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
CVSS Score
9.8
EPSS Score
0.003
Published
2019-10-09
The animate-it plugin before 2.3.4 for WordPress has XSS.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-09
The animate-it plugin before 2.3.5 for WordPress has XSS.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-10-09
"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BIND server which uses managed-keys to exit due to an assertion failure if, during key rollover, a trust anchor's keys are replaced with keys which use an unsupported algorithm. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.9.3-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5745.
CVSS Score
4.9
EPSS Score
0.006
Published
2019-10-09
The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an authenticated user with specific roles to perform cross-site scripting (XSS) attacks. This issue affects TIBCO Software Inc.'s TIBCO MDM version 9.0.1 and prior versions; version 9.1.0.
CVSS Score
6.3
EPSS Score
0.002
Published
2019-10-09
On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowledge. This feature of the Service Mode application is available after entering the *#9900# check code, but is protected by an OTP password. However, this password is created locally and (due to mishandling of cryptography) can be obtained easily by reversing the password creation logic.
CVSS Score
4.6
EPSS Score
0.0
Published
2019-10-09
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-10-09
An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without an integrity check, if a user changes personal data in his profile tab (e.g., exposure of his birthday) or logs into his account (i.e., exposure of credentials).
CVSS Score
6.8
EPSS Score
0.002
Published
2019-10-09
Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the total size of the headers stays below a maximum limit. The implementation in versions 1.10.0 through 1.11.1 for HTTP/1.x traffic and all versions of Envoy for HTTP/2 traffic had O(n^2) performance characteristics. A remote attacker may craft a request that stays below the maximum request header size but consists of many thousands of small headers to consume CPU and result in a denial-of-service attack.
CVSS Score
7.5
EPSS Score
0.131
Published
2019-10-09


Contact Us

Shodan ® - All rights reserved