CVE-2014-2387
- EPSS 0.1%
- Veröffentlicht 13.12.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 02:06:11
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
CVE-2014-0175
- EPSS 0.6%
- Veröffentlicht 13.12.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 02:01:33
mcollective has a default password set at install
CVE-2019-12420
- EPSS 13.68%
- Veröffentlicht 12.12.2019 23:15:12
- Zuletzt bearbeitet 21.11.2024 04:22:48
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly.
CVE-2018-11805
- EPSS 0.03%
- Veröffentlicht 12.12.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 03:44:04
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users...
CVE-2019-17358
- EPSS 2.42%
- Veröffentlicht 12.12.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:32:10
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti ...
CVE-2019-18345
- EPSS 1.09%
- Veröffentlicht 12.12.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:33:05
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in t...
CVE-2019-19725
- EPSS 0.25%
- Veröffentlicht 11.12.2019 18:16:20
- Zuletzt bearbeitet 21.11.2024 04:35:15
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
CVE-2019-19583
- EPSS 2.07%
- Veröffentlicht 11.12.2019 18:16:19
- Zuletzt bearbeitet 21.11.2024 04:34:59
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA...
CVE-2013-7371
- EPSS 0.58%
- Veröffentlicht 11.12.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 02:00:51
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
CVE-2013-4245
- EPSS 0.15%
- Veröffentlicht 11.12.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 01:55:12
Orca has arbitrary code execution due to insecure Python module load