CVE-2019-12473
- EPSS 0.47%
- Published 10.07.2019 16:15:11
- Last modified 21.11.2024 04:22:55
Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
CVE-2019-12474
- EPSS 0.26%
- Published 10.07.2019 16:15:11
- Last modified 21.11.2024 04:22:55
Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
CVE-2019-12467
- EPSS 0.3%
- Published 10.07.2019 15:15:12
- Last modified 21.11.2024 04:22:54
MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out spam with no rate limiting or ability to block them. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
CVE-2019-12468
- EPSS 0.52%
- Published 10.07.2019 15:15:12
- Last modified 21.11.2024 04:22:55
An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authentication, allowing for potential account takeover.
CVE-2019-13224
- EPSS 0.72%
- Published 10.07.2019 14:15:11
- Last modified 21.11.2024 04:24:29
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair o...
CVE-2019-13454
- EPSS 0.36%
- Published 09.07.2019 17:15:11
- Last modified 11.07.2025 20:05:48
ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
CVE-2018-11563
- EPSS 0.31%
- Published 08.07.2019 13:15:10
- Last modified 21.11.2024 03:43:37
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS c...
CVE-2019-13345
- EPSS 79.53%
- Published 05.07.2019 16:15:11
- Last modified 21.11.2024 04:24:45
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
CVE-2019-13297
- EPSS 0.4%
- Published 05.07.2019 01:15:10
- Last modified 21.11.2024 04:24:39
ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.
CVE-2019-13300
- EPSS 0.29%
- Published 05.07.2019 01:15:10
- Last modified 21.11.2024 04:24:39
ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.