Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2019-10-11 CVE-2019-2184 Out-of-bounds Write vulnerability in Google Android
In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds check.
network
low complexity
google CWE-787
8.8
2019-10-11 CVE-2019-2173 Incorrect Default Permissions vulnerability in Google Android
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check.
local
low complexity
google CWE-276
7.8
2019-10-11 CVE-2019-2114 Incorrect Default Permissions vulnerability in Google Android 8.0/8.1/9.0
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission.
local
low complexity
google CWE-276
7.8
2019-10-11 CVE-2015-9492 Information Exposure vulnerability in Smartit Premium Responsive Project Smartit Premium Responsive 20150515
The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9491 Information Exposure vulnerability in Blessing Premium Responsive Project Blessing Premium Responsive 20150515
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9490 Information Exposure vulnerability in Gamestheme Premium Project Gamestheme Premium 20150515
The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
network
low complexity
gamestheme-premium-project CWE-200
7.5
2019-10-11 CVE-2015-9489 Information Exposure vulnerability in Goodnex Premium Responsive Project Goodnex Premium Responsive 20150515
The ThemeMakers Goodnex Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9488 Information Exposure vulnerability in Almera Responsive Portfolio Site Template Project Almera Responsive Portfolio Site Template 20150515
The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9487 Information Exposure vulnerability in Almera Responsive Portfolio Project Almera Responsive Portfolio 20150515
The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5
2019-10-11 CVE-2015-9486 Information Exposure vulnerability in Axioma Premium Responsive Project Axioma Premium Responsive 20150515
The ThemeMakers Axioma Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
7.5