{"id":"CVE-2019-16752","details":"An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact that they are using the product. This also affects Dash Core through 0.14.0.3 and Private Instant Verified Transactions (PIVX) through 3.4.0.","modified":"2026-07-08T05:56:03.619648987Z","published":"2019-12-04T20:15:12.587Z","database_specific":{"unresolved_ranges":[{"vendor_product":"officialdapscoin:decentralized_anonymous_payment_system","cpes":["cpe:2.3:a:officialdapscoin:decentralized_anonymous_payment_system:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2019-08-26"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://officialdapscoin.com/wp-content/uploads/2019/09/DAPS-Coin-Final-Security-Audit-Red4Sec-2019.pdf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dashpay/dash","events":[{"introduced":"0"},{"last_affected":"7d8eab2641023c78a72ccd6efc99fc35fd030a46"}],"database_specific":{"cpe":"cpe:2.3:a:dash:dash_core:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.14.0.3"}],"source":"CPE_RANGE"}}],"versions":["v0.14.0.3","v0.14.0.2","v0.14.0.1","v0.14.0.0-rc6","v0.14.0.0","v0.14.0.0-rc5","v0.14.0.0-rc4","v0.14.0.0-rc3","v0.14.0.0-rc2","v0.14.0.0-rc1","v0.13.0.0-rc11","v0.13.0.0-rc10","v0.13.0.0-rc9","v0.13.0.0-rc8","v0.13.0.0-rc7","v0.13.0.0-rc6","v0.13.0.0-rc5","v0.13.0.0-rc4","v0.13.0.0-rc3","v0.13.0.0-rc2","v0.13.0.0-rc1","v0.12.3.2","v0.12.3.1","v0.12.2.3","v0.12.2.2","v0.12.1.4","v0.12.1.3","v0.12.1.2","v0.12.1.1","v0.12.1.0","v0.12.0.0","v0.11.2.22","v0.11.2.21","v0.11.2.17","v0.11.2.16","v0.11.1.25","v0.11.1.24","v0.11.1.23","v0.11.1.22","v0.11.1.21","v0.11.1.20","v0.11.0.14","v0.11.0.13","v0.11.0.12","v0.11.0.11","v0.11.0.10","v0.11.0.8","v0.11.0.7","v0.11.0.6","v0.11.0.5","v0.11.0.4","v0.11.0.3","v0.11.0.2","v0.11.0.0","v0.11.0.1","v0.8.0","v0.8.2","v0.7.1rc1","v0.7.1","v0.8.2rc2","v0.8.2rc3","v0.8.2rc1","v0.8.0rc1","v0.7.0rc3","v0.7.0","v0.7.0rc2","v0.7.0rc1","v0.6.0rc6","v0.6.0","v0.6.1","v0.5.0rc7","v0.5.0","v0.6.1rc2","v0.6.1rc1","v0.6.0rc5","v0.6.0rc4","v0.6.0rc3","v0.4.0","v0.6.0rc2","v0.6.0rc1","v0.5.1rc2","v0.5.1","v0.5.1rc1","v0.5.0rc6","v0.5.0rc5","v0.5.0rc4","v0.5.0rc2","v0.5.0rc1","v0.4.00rc2","v0.4.00rc1","v0.3.24","v0.3.24rc3","v0.3.24rc2","v0.3.24rc1","v0.3.23rc1","v0.3.23","v0.3.22","v0.3.22rc3","v0.3.22rc4","v0.3.22rc2","v0.3.22rc1","v0.3.21","v0.3.21rc","v0.3.20.2_closest","v0.3.20.01_closest","v0.3.20","v0.3.11_notexact","v0.3.8","v0.3.7","v0.3.6","v0.3.3","v0.3.2","v0.3.1","v0.3.1rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16752.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/pivx-project/pivx","events":[{"introduced":"0"},{"last_affected":"78e7e46fa8101a5576c6909d4edb0d9ce60ef44d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"3.4.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:pivx:private_instant_verified_transactions:*:*:*:*:*:*:*:*"}}],"versions":["v3.4.0","3.0.5.1-branchpoint","v2.1.7","v2.1.6","v2.1.4.0","v2.1.3.4","v2.1.3.3","v2.1.3.2","v2.1.3.1","v2.1.3.0","v2.1.2.3","v2.1.2.2","v2.1.2.1","v2.1.2.0","v2.1.1.0","v2.1.0.0","v2.0.5.0","v2.0.4.0","v2.0.3.0","v2.0.2.0","v2.0.1.0","v2.0.0.0","2.0.0.0","v1.1.0.2","v1.1.0.1","v1.1.0.0","v1.0.2.1","v1.0.2.0","v1.0.1.0","v1.0.0.0","v0.12.0.56","v0.12.0.55","v0.12.0.53","v0.12.0.52","v0.12.0.51","v0.12.0.49","v0.12.0.48","v0.12.0.47","v0.12.0.46","v0.12.0.45","v0.12.0.44","v0.11.2.23","v0.11.2.22","v0.11.2.21","v0.11.2.17","v0.11.2.16","v0.11.1.25","v0.11.1.24","v0.11.1.23","v0.11.1.22","v0.11.1.21","v0.11.1.20","v0.11.0.14","v0.11.0.13","v0.11.0.12","v0.11.0.11","v0.11.0.10","v0.11.0.8","v0.11.0.7","v0.11.0.6","v0.11.0.5","v0.11.0.4","v0.11.0.3","v0.11.0.2","v0.11.0.0","v0.11.0.1","v0.9.3","v0.9.3rc2","v0.9.3rc1","v0.9.2.1","v0.9.2","v0.9.2rc2","v0.9.2rc1","noversion","v0.9.0rc2","v0.8.0","v0.9.0rc1","v0.8.2","v0.7.1rc1","v0.7.1","v0.8.2rc2","v0.8.2rc3","v0.8.2rc1","v0.8.0rc1","v0.7.0rc3","v0.7.0","v0.7.0rc2","v0.7.0rc1","v0.6.0rc6","v0.6.0","v0.6.1","v0.5.0rc7","v0.5.0","v0.6.1rc2","v0.6.1rc1","v0.6.0rc5","v0.6.0rc4","v0.6.0rc3","v0.4.0","v0.6.0rc2","v0.6.0rc1","v0.5.1rc2","v0.5.1","v0.5.1rc1","v0.5.0rc6","v0.5.0rc5","v0.5.0rc4","v0.5.0rc2","v0.5.0rc1","v0.4.00rc2","v0.4.00rc1","v0.3.24","v0.3.24rc3","v0.3.24rc2","v0.3.24rc1","v0.3.23rc1","v0.3.23","v0.3.22","v0.3.22rc3","v0.3.22rc4","v0.3.22rc2","v0.3.22rc1","v0.3.21","v0.3.21rc","v0.3.20.2_closest","v0.3.20.01_closest","v0.3.20","v0.3.11_notexact","v0.3.8","v0.3.7","v0.3.6","v0.3.3","v0.3.2","v0.3.1","v0.3.1rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16752.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}]}