CVE-2019-16775
- EPSS 0.72%
- Veröffentlicht 13.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:09
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the ...
CVE-2019-16776
- EPSS 0.83%
- Veröffentlicht 13.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:10
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field wou...
CVE-2019-13734
- EPSS 5.9%
- Veröffentlicht 10.12.2019 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:25:36
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-19333
- EPSS 0.74%
- Veröffentlicht 06.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:35
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, whi...
CVE-2019-19334
- EPSS 0.78%
- Veröffentlicht 06.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:35
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this fl...
CVE-2019-19624
- EPSS 0.23%
- Veröffentlicht 06.12.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:04
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing w...
CVE-2019-13456
- EPSS 0.24%
- Veröffentlicht 03.12.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:56
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the pa...
CVE-2013-4235
- EPSS 0.06%
- Veröffentlicht 03.12.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:11
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
CVE-2019-19319
- EPSS 0.44%
- Veröffentlicht 27.11.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:34
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a mem...
CVE-2019-18660
- EPSS 0.03%
- Veröffentlicht 27.11.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:28
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security....