CVE-2019-19479
- EPSS 0.05%
- Published 01.12.2019 23:15:10
- Last modified 21.11.2024 04:34:48
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
CVE-2019-18609
- EPSS 2.76%
- Published 01.12.2019 22:15:10
- Last modified 21.11.2024 04:33:21
An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header ...
CVE-2019-19269
- EPSS 1.78%
- Published 30.11.2019 23:15:18
- Last modified 21.11.2024 04:34:27
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrato...
CVE-2019-19462
- EPSS 0.1%
- Published 30.11.2019 01:15:10
- Last modified 21.11.2024 04:34:47
relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.
CVE-2014-3591
- EPSS 0.14%
- Published 29.11.2019 22:15:11
- Last modified 21.11.2024 02:08:27
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluct...
CVE-2015-0837
- EPSS 0.55%
- Published 29.11.2019 22:15:11
- Last modified 21.11.2024 02:23:49
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cach...
CVE-2015-1855
- EPSS 2.72%
- Published 29.11.2019 21:15:10
- Last modified 21.11.2024 02:26:16
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multi...
- EPSS 6.73%
- Published 29.11.2019 15:15:11
- Last modified 21.11.2024 04:27:38
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary co...
CVE-2019-14897
- EPSS 0.87%
- Published 29.11.2019 15:15:10
- Last modified 21.11.2024 04:27:38
A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allow...
CVE-2019-14895
- EPSS 3%
- Published 29.11.2019 14:15:11
- Last modified 21.11.2024 04:27:37
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote device...