CVE-2013-7370
- EPSS 1.08%
- Published 11.12.2019 14:15:09
- Last modified 21.11.2024 02:00:51
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
CVE-2013-4158
- EPSS 0.63%
- Published 11.12.2019 13:15:10
- Last modified 21.11.2024 01:54:59
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
CVE-2019-19709
- EPSS 0.32%
- Published 11.12.2019 02:15:14
- Last modified 21.11.2024 04:35:14
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that...
CVE-2019-5815
- EPSS 0.11%
- Published 11.12.2019 01:15:10
- Last modified 21.11.2024 04:45:33
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
CVE-2019-19604
- EPSS 1.34%
- Published 11.12.2019 00:15:13
- Last modified 21.11.2024 04:35:02
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a ma...
CVE-2019-14861
- EPSS 1.65%
- Published 10.12.2019 23:15:10
- Last modified 21.11.2024 04:27:31
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stor...
CVE-2019-14870
- EPSS 4.67%
- Published 10.12.2019 23:15:10
- Last modified 21.11.2024 04:27:33
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in an...
CVE-2019-14889
- EPSS 0.62%
- Published 10.12.2019 23:15:10
- Last modified 21.11.2024 04:27:37
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the ...
CVE-2019-13753
- EPSS 4.17%
- Published 10.12.2019 22:15:15
- Last modified 21.11.2024 04:25:39
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVE-2019-13754
- EPSS 0.28%
- Published 10.12.2019 22:15:15
- Last modified 21.11.2024 04:25:39
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.