CVE-2007-6745
- EPSS 0.65%
- Published 07.11.2019 23:15:10
- Last modified 21.11.2024 00:40:54
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
CVE-2013-1809
- EPSS 1.7%
- Published 07.11.2019 23:15:10
- Last modified 21.11.2024 01:50:25
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
CVE-2013-1811
- EPSS 0.33%
- Published 07.11.2019 23:15:10
- Last modified 21.11.2024 01:50:26
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
CVE-2007-5743
- EPSS 0.35%
- Published 07.11.2019 22:15:10
- Last modified 21.11.2024 00:38:36
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
CVE-2013-1429
- EPSS 1%
- Published 07.11.2019 22:15:10
- Last modified 21.11.2024 01:49:33
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
CVE-2010-2450
- EPSS 0.16%
- Published 07.11.2019 21:15:10
- Last modified 21.11.2024 01:16:41
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself,...
CVE-2013-1425
- EPSS 0.1%
- Published 07.11.2019 21:15:10
- Last modified 21.11.2024 01:49:33
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
CVE-2019-3465
- EPSS 3.05%
- Published 07.11.2019 20:15:11
- Last modified 21.11.2024 04:42:06
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by...
CVE-2012-0049
- EPSS 0.62%
- Published 07.11.2019 18:15:11
- Last modified 21.11.2024 01:34:17
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
CVE-2012-0051
- EPSS 1.36%
- Published 07.11.2019 18:15:11
- Last modified 21.11.2024 01:34:17
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.