CVE-2021-4034
- EPSS 86.52%
- Veröffentlicht 28.01.2022 20:15:12
- Zuletzt bearbeitet 03.04.2025 18:53:12
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pk...
CVE-2019-11038
- EPSS 8.29%
- Veröffentlicht 19.06.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:20:25
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause t...
- EPSS 27.65%
- Veröffentlicht 03.01.2018 06:29:00
- Zuletzt bearbeitet 03.01.2025 12:15:25
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other im...
CVE-2016-9957
- EPSS 0.29%
- Veröffentlicht 12.04.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in game-music-emu before 0.6.1.
CVE-2016-9958
- EPSS 0.31%
- Veröffentlicht 12.04.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
CVE-2016-9959
- EPSS 0.31%
- Veröffentlicht 12.04.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
CVE-2014-9852
- EPSS 1.32%
- Veröffentlicht 17.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
CVE-2014-9853
- EPSS 0.47%
- Veröffentlicht 17.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
CVE-2016-5244
- EPSS 0.77%
- Veröffentlicht 27.06.2016 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
- EPSS 24.52%
- Veröffentlicht 16.06.2016 14:59:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.