CVE-2019-19911
- EPSS 0.97%
- Published 05.01.2020 22:15:11
- Last modified 21.11.2024 04:35:38
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryE...
CVE-2019-20330
- EPSS 1.86%
- Published 03.01.2020 04:15:12
- Last modified 21.11.2024 04:38:16
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2020-5311
- EPSS 1.3%
- Published 03.01.2020 01:15:11
- Last modified 21.11.2024 05:33:53
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
CVE-2020-5312
- EPSS 1.73%
- Published 03.01.2020 01:15:11
- Last modified 21.11.2024 05:33:53
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
CVE-2020-5313
- EPSS 0.55%
- Published 03.01.2020 01:15:11
- Last modified 21.11.2024 05:33:53
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
CVE-2014-8182
- EPSS 5.15%
- Published 02.01.2020 23:15:11
- Last modified 21.11.2024 02:18:43
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
CVE-2014-6275
- EPSS 0.33%
- Published 02.01.2020 22:15:11
- Last modified 21.11.2024 02:14:04
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk priva...
CVE-2013-4532
- EPSS 0.17%
- Published 02.01.2020 16:15:11
- Last modified 21.11.2024 01:55:45
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
CVE-2019-14864
- EPSS 0.94%
- Published 02.01.2020 15:15:12
- Last modified 21.11.2024 04:27:31
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...
CVE-2019-20208
- EPSS 0.51%
- Published 02.01.2020 14:16:36
- Last modified 11.07.2025 20:06:49
dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.