CVE-2019-20014
- EPSS 0.51%
- Published 27.12.2019 01:15:13
- Last modified 21.11.2024 04:37:53
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
CVE-2019-20015
- EPSS 0.58%
- Published 27.12.2019 01:15:13
- Last modified 21.11.2024 04:37:53
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec.
CVE-2019-19925
- EPSS 9.23%
- Published 24.12.2019 17:15:10
- Last modified 21.11.2024 04:35:40
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
CVE-2019-19923
- EPSS 10.52%
- Published 24.12.2019 16:15:11
- Last modified 21.11.2024 04:35:40
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
CVE-2019-19926
- EPSS 8.34%
- Published 23.12.2019 01:15:13
- Last modified 21.11.2024 04:35:41
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
CVE-2019-19917
- EPSS 0.36%
- Published 20.12.2019 20:15:12
- Last modified 21.11.2024 04:35:39
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
CVE-2019-19918
- EPSS 0.37%
- Published 20.12.2019 20:15:12
- Last modified 21.11.2024 04:35:39
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
CVE-2019-19880
- EPSS 8.44%
- Published 18.12.2019 06:15:12
- Last modified 21.11.2024 04:35:34
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
CVE-2019-16779
- EPSS 0.56%
- Published 16.12.2019 20:15:15
- Last modified 21.11.2024 04:31:10
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content ...
CVE-2019-13764
- EPSS 38.69%
- Published 10.12.2019 22:15:15
- Last modified 21.11.2024 04:25:40
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.