CVE-2017-5332
- EPSS 0.23%
- Veröffentlicht 04.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:27:24
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
CVE-2017-5333
- EPSS 0.23%
- Veröffentlicht 04.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:27:24
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
CVE-2013-4251
- EPSS 0.09%
- Veröffentlicht 04.11.2019 20:15:09
- Zuletzt bearbeitet 21.11.2024 01:55:13
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
CVE-2005-4890
- EPSS 0.12%
- Veröffentlicht 04.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 00:05:25
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by...
- EPSS 1.06%
- Veröffentlicht 04.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:31
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. ...
CVE-2013-4412
- EPSS 0.94%
- Veröffentlicht 04.11.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:31
slim has NULL pointer dereference when using crypt() method from glibc 2.17
CVE-2013-4168
- EPSS 0.58%
- Veröffentlicht 01.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:00
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
CVE-2005-2351
- EPSS 0.13%
- Veröffentlicht 01.11.2019 19:15:10
- Zuletzt bearbeitet 20.11.2024 23:59:21
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
CVE-2013-2255
- EPSS 0.41%
- Veröffentlicht 01.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:51:20
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
CVE-2013-2227
- EPSS 31.19%
- Veröffentlicht 01.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 01:51:17
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.