CVE-2012-1168
- EPSS 2.22%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:34
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2011-1145
- EPSS 0.22%
- Veröffentlicht 14.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 01:25:39
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
CVE-2010-4664
- EPSS 0.2%
- Veröffentlicht 13.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:28
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
CVE-2010-4657
- EPSS 1.57%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
CVE-2010-4661
- EPSS 0.15%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
CVE-2011-2897
- EPSS 0.99%
- Veröffentlicht 12.11.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 01:29:13
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
CVE-2019-14824
- EPSS 0.2%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:26
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
CVE-2019-18811
- EPSS 0.13%
- Veröffentlicht 07.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:37
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380...
CVE-2019-18805
- EPSS 0.57%
- Veröffentlicht 07.11.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:36
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen...
CVE-2016-1000037
- EPSS 0.49%
- Veröffentlicht 06.11.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 02:42:51
Pagure: XSS possible in file attachment endpoint