CVE-2019-12523
- EPSS 0.56%
- Veröffentlicht 26.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:01
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...
CVE-2019-12526
- EPSS 33.64%
- Veröffentlicht 26.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:02
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...
CVE-2011-4350
- EPSS 25.88%
- Veröffentlicht 26.11.2019 05:15:14
- Zuletzt bearbeitet 21.11.2024 01:32:17
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.
CVE-2011-4120
- EPSS 1.48%
- Veröffentlicht 26.11.2019 05:15:13
- Zuletzt bearbeitet 21.11.2024 01:31:53
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common...
CVE-2011-4082
- EPSS 0.92%
- Veröffentlicht 26.11.2019 05:15:11
- Zuletzt bearbeitet 21.11.2024 01:31:48
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.
CVE-2011-3631
- EPSS 4.16%
- Veröffentlicht 26.11.2019 04:15:11
- Zuletzt bearbeitet 21.11.2024 01:30:53
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a speciall...
CVE-2011-3632
- EPSS 0.13%
- Veröffentlicht 26.11.2019 04:15:11
- Zuletzt bearbeitet 21.11.2024 01:30:53
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
CVE-2011-3630
- EPSS 3.12%
- Veröffentlicht 26.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 01:30:53
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user...
CVE-2011-3617
- EPSS 0.28%
- Veröffentlicht 26.11.2019 03:15:10
- Zuletzt bearbeitet 21.11.2024 01:30:51
Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.
CVE-2011-3374
- EPSS 1.51%
- Veröffentlicht 26.11.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 01:30:22
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.