CVE-2019-17022
- EPSS 4.63%
- Veröffentlicht 08.01.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:31:33
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direc...
CVE-2019-17023
- EPSS 0.9%
- Veröffentlicht 08.01.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:31:33
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored....
CVE-2019-17024
- EPSS 3.28%
- Veröffentlicht 08.01.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:31:34
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...
CVE-2019-11745
- EPSS 0.81%
- Veröffentlicht 08.01.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:21:42
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerabilit...
CVE-2019-20367
- EPSS 2.64%
- Veröffentlicht 08.01.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:19
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
CVE-2019-5188
- EPSS 0.04%
- Veröffentlicht 08.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:31
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partit...
CVE-2020-0009
- EPSS 0.12%
- Veröffentlicht 08.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:44
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privilege...
CVE-2019-18625
- EPSS 0.25%
- Veröffentlicht 06.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:23
An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil server. After the TCP SYN packet, it is possible to inject a RST ACK and a FIN ACK packet with a bad TCP T...
CVE-2019-18179
- EPSS 0.52%
- Veröffentlicht 06.01.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:32:46
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, ...
CVE-2019-18792
- EPSS 0.18%
- Veröffentlicht 06.01.2020 18:15:23
- Zuletzt bearbeitet 21.11.2024 04:33:34
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The PUSH ACK pac...