CVE-2019-11135
- EPSS 0.24%
- Veröffentlicht 14.11.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:20:35
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2019-10219
- EPSS 1.67%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-16056
- EPSS 0.58%
- Veröffentlicht 06.09.2019 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:29:57
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and imple...
CVE-2019-13057
- EPSS 1.14%
- Veröffentlicht 26.07.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:24:07
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not pro...
CVE-2019-13565
- EPSS 5.75%
- Veröffentlicht 26.07.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:11
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simpl...
CVE-2019-13038
- EPSS 0.12%
- Veröffentlicht 29.06.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 04:24:05
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
CVE-2019-12387
- EPSS 0.54%
- Veröffentlicht 10.06.2019 12:29:00
- Zuletzt bearbeitet 25.11.2024 18:12:24
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
CVE-2018-20781
- EPSS 4.7%
- Veröffentlicht 12.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:09
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.