CVE-2019-19221
- EPSS 0.07%
- Veröffentlicht 21.11.2019 23:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:21
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
- EPSS 0.09%
- Veröffentlicht 21.11.2019 23:15:12
- Zuletzt bearbeitet 21.11.2024 02:11:42
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.
CVE-2019-19204
- EPSS 8.95%
- Veröffentlicht 21.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:19
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
CVE-2019-18890
- EPSS 28.95%
- Veröffentlicht 21.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:47
A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.
CVE-2019-5087
- EPSS 0.19%
- Veröffentlicht 21.11.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:19
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to cor...
CVE-2019-5086
- EPSS 0.2%
- Veröffentlicht 21.11.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:19
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt mem...
CVE-2014-1936
- EPSS 0.43%
- Veröffentlicht 21.11.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 02:05:18
rc before 1.7.1-5 insecurely creates temporary files.
CVE-2014-1935
- EPSS 0.47%
- Veröffentlicht 21.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:05:18
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
CVE-2014-0083
- EPSS 0.07%
- Veröffentlicht 21.11.2019 14:15:13
- Zuletzt bearbeitet 21.11.2024 02:01:19
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
CVE-2012-2350
- EPSS 0.43%
- Veröffentlicht 21.11.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 01:38:55
pam_shield before 0.9.4: Default configuration does not perform protective action