CVE-2020-10663
- EPSS 6.54%
- Veröffentlicht 28.04.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:55:47
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavi...
CVE-2019-14899
- EPSS 0.05%
- Veröffentlicht 11.12.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:27:38
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiti...
CVE-2019-13118
- EPSS 1.21%
- Veröffentlicht 01.07.2019 02:15:09
- Zuletzt bearbeitet 21.11.2024 04:24:13
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
CVE-2013-0340
- EPSS 0.04%
- Veröffentlicht 21.01.2014 18:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to i...
CVE-2001-0102
- EPSS 0.05%
- Veröffentlicht 12.02.2001 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a passwor...
- EPSS 12.39%
- Veröffentlicht 01.06.2000 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
A system does not present an appropriate legal message or warning to a user who is accessing it.
- EPSS 0.5%
- Veröffentlicht 28.12.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.
CVE-1999-1077
- EPSS 0.06%
- Veröffentlicht 01.11.1999 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.
CVE-1999-1076
- EPSS 0.06%
- Veröffentlicht 26.10.1999 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants...
CVE-1999-1543
- EPSS 0.31%
- Veröffentlicht 10.07.1999 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.