CVE-2019-5736
- EPSS 53.41%
- Published 11.02.2019 19:29:00
- Last modified 21.11.2024 04:45:24
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types ...
CVE-2019-7635
- EPSS 5.49%
- Published 08.02.2019 11:29:00
- Last modified 21.11.2024 04:48:26
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
CVE-2019-7548
- EPSS 1.11%
- Published 06.02.2019 21:29:01
- Last modified 21.11.2024 04:48:18
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
CVE-2018-16873
- EPSS 63.39%
- Published 14.12.2018 14:29:00
- Last modified 21.11.2024 03:53:29
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically,...
CVE-2018-16874
- EPSS 12.67%
- Published 14.12.2018 14:29:00
- Last modified 21.11.2024 03:53:30
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only v...
CVE-2018-19052
- EPSS 37.42%
- Published 07.11.2018 05:29:00
- Last modified 21.11.2024 03:57:14
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a...