CVE-2019-19012
- EPSS 14.78%
- Veröffentlicht 17.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:59
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). ...
CVE-2011-2726
- EPSS 0.38%
- Veröffentlicht 15.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 01:28:50
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory ...
CVE-2016-5285
- EPSS 0.65%
- Veröffentlicht 15.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:53:59
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
CVE-2019-11135
- EPSS 0.32%
- Veröffentlicht 14.11.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:20:35
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2012-1155
- EPSS 1.27%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:33
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
CVE-2012-1156
- EPSS 1.23%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:33
Moodle before 2.2.2 has users' private files included in course backups
CVE-2012-1168
- EPSS 2.22%
- Veröffentlicht 14.11.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 01:36:34
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
CVE-2011-1145
- EPSS 0.22%
- Veröffentlicht 14.11.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 01:25:39
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
CVE-2010-4664
- EPSS 0.2%
- Veröffentlicht 13.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:28
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
CVE-2010-4657
- EPSS 1.57%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.