WAFPlanet

CVE Database - 2019

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

6997
Matching CVEs
15562
Critical
25943
High
66770
High WAF Coverage

CVE-2019-11108

MEDIUM
6.70 CVSS 3.1

Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.

Improper Input Validation
WAF: Medium

CVE-2019-11107

CRITICAL
9.80 CVSS 3.1

Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

Improper Input Validation
WAF: Medium

CVE-2019-11104

HIGH
7.80 CVSS 3.1

Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

Improper Input Validation
WAF: Medium

CVE-2019-11103

HIGH
7.80 CVSS 3.1

Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

Improper Input Validation
WAF: Medium

CVE-2019-11102

MEDIUM
4.40 CVSS 3.1

Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

Improper Input Validation
WAF: Medium

CVE-2019-11101

MEDIUM
4.40 CVSS 3.1

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

Improper Input Validation
WAF: Medium

CVE-2019-11100

MEDIUM
4.60 CVSS 3.1

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

Improper Input Validation
WAF: Medium

CVE-2019-11088

HIGH
8.80 CVSS 3.1

Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

Improper Input Validation
WAF: Medium

CVE-2019-11087

MEDIUM
6.70 CVSS 3.1

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

Improper Input Validation
WAF: Medium

CVE-2019-11086

MEDIUM
6.80 CVSS 3.1

Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Improper Input Validation
WAF: Medium

CVE-2019-0168

MEDIUM
4.40 CVSS 3.1

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

Improper Input Validation
WAF: Medium

CVE-2019-0166

HIGH
7.50 CVSS 3.1

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

Improper Input Validation
WAF: Medium

CVE-2019-0165

MEDIUM
4.40 CVSS 3.1

Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.

Improper Input Validation
WAF: Medium

CVE-2019-0131

HIGH
8.10 CVSS 3.1

Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

Improper Input Validation
WAF: Medium

CVE-2019-5486

HIGH
8.80 CVSS 3.1

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

Improper Authentication
WAF: Low

CVE-2019-18995

MEDIUM
5.30 CVSS 3.1

The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.

Improper Input Validation
WAF: Medium

CVE-2019-18994

MEDIUM
6.50 CVSS 3.1

Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.

Improper Input Validation
WAF: Medium

CVE-2019-18571

MEDIUM
5.40 CVSS 3.1

The RSA Identity Governance and Lifecycle and RSA Via Lifecycle and Governance products prior to 7.1.1 P03 contain a reflected cross-site scripting vulnerability in the My Access Live module [MAL]. An authenticated malicious local user could potentially exploit this vulnerability by sending crafted URL with scripts. When victim users access the module through their browsers, the malicious code gets injected and executed by the web browser in the context of the vulnerable web application.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-15600

HIGH
7.50 CVSS 3.1

A Path traversal exists in http_server which allows an attacker to read arbitrary system files.

Path Traversal
WAF: High

CVE-2019-15599

CRITICAL
9.80 CVSS 3.1

A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

Code Injection
WAF: Medium

CVE-2019-15598

CRITICAL
9.80 CVSS 3.1

A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

Code Injection OS Command Injection
WAF: High

CVE-2019-15597

CRITICAL
9.80 CVSS 3.1

A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.

Code Injection
WAF: Medium

CVE-2019-15596

HIGH
7.50 CVSS 3.1

A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.

Path Traversal
WAF: High

CVE-2019-15576

HIGH
7.50 CVSS 3.1

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.

Missing Authorization
WAF: Low

CVE-2019-15575

HIGH
7.50 CVSS 3.1

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

Command Injection
WAF: High

CVE-2019-7621

MEDIUM
5.40 CVSS 3.1

Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with the ability to create coordinate map visualizations could create a malicious visualization. If another Kibana user views that visualization or a dashboard containing the visualization it could execute JavaScript in the victim�s browser.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-18267

MEDIUM
5.40 CVSS 3.1

An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.

Cross-Site Scripting (XSS)
WAF: High

CVE-2012-2656

HIGH
7.50 CVSS 3.1

An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.

XML External Entity (XXE)
WAF: High

CVE-2019-8817

MEDIUM
5.50 CVSS 3.1

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.1. An application may be able to read restricted memory.

Improper Input Validation
WAF: Medium

CVE-2019-8813

MEDIUM
6.10 CVSS 3.1

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0. Processing maliciously crafted web content may lead to universal cross site scripting.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-8804

MEDIUM
5.70 CVSS 3.1

An inconsistency in Wi-Fi network configuration settings was addressed. This issue is fixed in iOS 13.2 and iPadOS 13.2. An attacker in physical proximity may be able to force a user onto a malicious Wi-Fi network during device setup.

Improper Authentication
WAF: Low

CVE-2019-8802

HIGH
7.80 CVSS 3.1

A validation issue was addressed with improved logic. This issue is fixed in macOS Catalina 10.15.1. A malicious application may be able to gain root privileges.

Improper Input Validation
WAF: Medium

CVE-2019-8794

MEDIUM
5.50 CVSS 3.1

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1, tvOS 13.2, watchOS 6.1. An application may be able to read restricted memory.

Improper Input Validation
WAF: Medium

CVE-2019-8791

MEDIUM
6.10 CVSS 3.1

An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.

Open Redirect
WAF: Medium

CVE-2019-8788

HIGH
7.50 CVSS 3.1

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 13.2 and iPadOS 13.2, macOS Catalina 10.15.1. Improper URL processing may lead to data exfiltration.

Improper Input Validation
WAF: Medium

CVE-2019-8764

MEDIUM
6.10 CVSS 3.1

A logic issue was addressed with improved state management. This issue is fixed in watchOS 6.1. Processing maliciously crafted web content may lead to universal cross site scripting.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-8760

MEDIUM
6.80 CVSS 3.1

This issue was addressed by improving Face ID machine learning models. This issue is fixed in iOS 13. A 3D model constructed to look like the enrolled user may authenticate via Face ID.

Improper Authentication
WAF: Low

CVE-2019-8724

HIGH
8.80 CVSS 3.1

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

Improper Input Validation
WAF: Medium

CVE-2019-8723

HIGH
8.80 CVSS 3.1

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

Improper Input Validation
WAF: Medium

CVE-2019-8722

HIGH
8.80 CVSS 3.1

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

Improper Input Validation
WAF: Medium

CVE-2019-8721

HIGH
8.80 CVSS 3.1

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.

Improper Input Validation
WAF: Medium

CVE-2019-8719

MEDIUM
6.10 CVSS 3.1

A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Windows 7.14. Processing maliciously crafted web content may lead to universal cross site scripting.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-8711

MEDIUM
5.30 CVSS 3.1

A logic issue existed with the display of notification previews. This issue was addressed with improved validation. This issue is fixed in iOS 13. Notification previews may show on Bluetooth accessories even when previews are disabled.

Improper Input Validation
WAF: Medium

CVE-2019-8704

MEDIUM
5.50 CVSS 3.1

An authentication issue was addressed with improved state management. This issue is fixed in tvOS 13. A local user may be able to leak sensitive user information.

Improper Authentication
WAF: Low

CVE-2019-8698

LOW
3.30 CVSS 3.1

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.

Improper Input Validation
WAF: Medium

CVE-2019-8690

MEDIUM
6.10 CVSS 3.1

A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to universal cross site scripting.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-8674

MEDIUM
6.10 CVSS 3.1

A logic issue was addressed with improved state management. This issue is fixed in iOS 13, Safari 13. Processing maliciously crafted web content may lead to universal cross site scripting.

Cross-Site Scripting (XSS)
WAF: High

CVE-2019-8670

MEDIUM
4.30 CVSS 3.1

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.6, Safari 12.1.2. Visiting a malicious website may lead to address bar spoofing.

Improper Input Validation
WAF: Medium

CVE-2019-8665

HIGH
7.50 CVSS 3.1

A denial of service issue was addressed with improved validation. This issue is fixed in iOS 12.4, watchOS 5.3. A remote attacker may cause an unexpected application termination.

Improper Input Validation
WAF: Medium

CVE-2019-8662

CRITICAL
9.80 CVSS 3.1

This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3. An attacker may be able to trigger a use-after-free in an application deserializing an untrusted NSDictionary.

Insecure Deserialization
WAF: Medium
Page 5 of 140 (6997 CVEs)