CVE-2019-0 to CVE-2019-999
62 CVEs with public proof-of-concept exploits.
- CVE-2019-00531 PoCJunos OS: Insufficient validation of environment variables in telnet client may lead to stack-based buffer overflow
- CVE-2019-01862 PoCsThe input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XSS) attacks.…
- CVE-2019-01923 PoCsIn Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By…
- CVE-2019-019311 PoCsKEVIn Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in…
- CVE-2019-02071 PoCTapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, which doesn't…
- CVE-2019-02117 PoCsKEVIn Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes…
- CVE-2019-02171 PoCIn Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a…
- CVE-2019-02212 PoCsThe SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without…
- CVE-2019-02221 PoCIn Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
- CVE-2019-02251 PoCA specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2,…
- CVE-2019-02274 PoCsA Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and…
- CVE-2019-023017 PoCsApache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code…
- CVE-2019-023219 PoCsWhen running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and…
- CVE-2019-02357 PoCsApache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
- CVE-2019-02851 PoCThe .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive database information…
- CVE-2019-03072 PoCsDiagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user…
- CVE-2019-03191 PoCThe SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form of an error…
- CVE-2019-05399 PoCsA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2019-05412 PoCsKEVA remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code…
- CVE-2019-05431 PoCKEVAn elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation…
- CVE-2019-05521 PoCAn elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." This affects…
- CVE-2019-05552 PoCsAn elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the…
- CVE-2019-05661 PoCAn elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege…
- CVE-2019-05676 PoCsA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2019-05681 PoCA remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka…
- CVE-2019-05701 PoCAn elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windows Runtime…
- CVE-2019-05711 PoCAn elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data…
- CVE-2019-05721 PoCAn elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data…
- CVE-2019-05731 PoCAn elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data…
- CVE-2019-05741 PoCAn elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data…
- CVE-2019-060415 PoCsKEVA remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application…
- CVE-2019-06121 PoCA security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself,…
- CVE-2019-06232 PoCsAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2019-06671 PoCA remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine…
- CVE-2019-06782 PoCsAn elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an…
- CVE-2019-07031 PoCKEVAn information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB…
- CVE-2019-0708142 PoCsKEVA remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated…
- CVE-2019-07092 PoCsWindows Hyper-V Remote Code Execution Vulnerability
- CVE-2019-07241 PoCAn elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege…
- CVE-2019-07301 PoCAn elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows…
- CVE-2019-07311 PoCAn elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows…
- CVE-2019-07321 PoCA security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly…
- CVE-2019-07351 PoCAn elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects…
- CVE-2019-07524 PoCsKEVA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka…
- CVE-2019-07684 PoCsA security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under…
- CVE-2019-07851 PoCA memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP…
- CVE-2019-07961 PoCAn elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows…
- CVE-2019-08039 PoCsKEVAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2019-08051 PoCAn elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows…
- CVE-2019-08087 PoCsKEVAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2019-08201 PoCA denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET…
- CVE-2019-08361 PoCAn elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows…
- CVE-2019-084112 PoCsKEVAn elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows…
- CVE-2019-08591 PoCKEVAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2019-08631 PoCKEVAn elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting…
- CVE-2019-08811 PoCAn elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows Kernel Elevation…
- CVE-2019-08872 PoCsA remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated…
- CVE-2019-08881 PoCActiveX Data Objects (ADO) Remote Code Execution Vulnerability
- CVE-2019-09431 PoCWindows ALPC Elevation of Privilege Vulnerability
- CVE-2019-09481 PoCWindows Event Viewer Information Disclosure Vulnerability
- CVE-2019-09591 PoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2019-09861 PoCWindows User Profile Service Elevation of Privilege Vulnerability