CVE-2010-3439
- EPSS 0.57%
- Veröffentlicht 12.11.2019 20:15:09
- Zuletzt bearbeitet 21.11.2024 01:18:44
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
CVE-2010-3359
- EPSS 0.13%
- Veröffentlicht 12.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:34
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked libgarglk.so and gain access t...
CVE-2012-1572
- EPSS 0.42%
- Veröffentlicht 12.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 01:37:14
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
CVE-2011-3618
- EPSS 0.11%
- Veröffentlicht 12.11.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:30:51
atop: symlink attack possible due to insecure tempfile handling
CVE-2019-18848
- EPSS 0.48%
- Veröffentlicht 12.11.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:42
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
CVE-2011-2897
- EPSS 0.99%
- Veröffentlicht 12.11.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 01:29:13
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
CVE-2019-18849
- EPSS 1.02%
- Veröffentlicht 11.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:42
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
CVE-2009-3614
- EPSS 0.12%
- Veröffentlicht 09.11.2019 03:15:10
- Zuletzt bearbeitet 21.11.2024 01:07:48
liboping 1.3.2 allows users reading arbitrary files upon the local system.
CVE-2019-14824
- EPSS 0.2%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:26
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
CVE-2008-7291
- EPSS 0.43%
- Veröffentlicht 08.11.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 00:58:45
gri before 2.12.18 generates temporary files in an insecure way.