CVE-2019-14870
- EPSS 4.67%
- Published 10.12.2019 23:15:10
- Last modified 21.11.2024 04:27:33
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in an...
CVE-2019-14889
- EPSS 0.88%
- Published 10.12.2019 23:15:10
- Last modified 21.11.2024 04:27:37
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the ...
CVE-2019-1551
- EPSS 4.53%
- Published 06.12.2019 18:15:12
- Last modified 21.11.2024 04:36:48
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this d...
CVE-2019-3690
- EPSS 0.1%
- Published 05.12.2019 16:15:11
- Last modified 21.11.2024 04:42:20
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control over a path that is traversed...
CVE-2019-19553
- EPSS 0.66%
- Published 05.12.2019 01:15:14
- Last modified 21.11.2024 04:34:57
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.
CVE-2015-7542
- EPSS 0.11%
- Published 03.12.2019 23:15:11
- Last modified 21.11.2024 02:36:56
A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
CVE-2019-5163
- EPSS 0.49%
- Published 03.12.2019 22:15:15
- Last modified 21.11.2024 04:44:28
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send...
CVE-2019-5164
- EPSS 0.43%
- Published 03.12.2019 22:15:15
- Last modified 21.11.2024 04:44:28
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. A...
CVE-2016-1000104
- EPSS 0.41%
- Published 03.12.2019 22:15:13
- Last modified 21.11.2024 02:42:52
A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
CVE-2019-13456
- EPSS 0.28%
- Published 03.12.2019 20:15:11
- Last modified 21.11.2024 04:24:56
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the pa...