CVE-2019-14981
- EPSS 0.67%
- Veröffentlicht 12.08.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:49
In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file.
CVE-2019-11041
- EPSS 2.82%
- Veröffentlicht 09.08.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:25
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past ...
CVE-2019-11042
- EPSS 3.29%
- Veröffentlicht 09.08.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:25
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past ...
CVE-2019-14806
- EPSS 0.22%
- Veröffentlicht 09.08.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:23
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
CVE-2019-13106
- EPSS 0.85%
- Veröffentlicht 06.08.2019 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:24:11
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.
CVE-2019-13104
- EPSS 0.29%
- Veröffentlicht 06.08.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:11
In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
CVE-2019-14235
- EPSS 4.54%
- Veröffentlicht 02.08.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:26:15
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain inputs, django.utils.encoding.uri_to_iri could lead to significant memory usage due to a recursion when repercent-encoding invalid...
CVE-2019-14232
- EPSS 3.63%
- Veröffentlicht 02.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:15
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.text.Truncator's chars() and words() methods were passed the html=True argument, they were extremely slow to evaluate certain inputs...
CVE-2019-14233
- EPSS 4.68%
- Veröffentlicht 02.08.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:15
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behaviour of the underlying HTMLParser, django.utils.html.strip_tags would be extremely slow to evaluate certain inputs containing large ...
CVE-2019-14524
- EPSS 0.48%
- Veröffentlicht 02.08.2019 12:15:12
- Zuletzt bearbeitet 21.11.2024 04:26:53
An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465.