CVE-2019-16220
- EPSS 0.82%
- Veröffentlicht 11.09.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:18
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
CVE-2019-16163
- EPSS 0.09%
- Veröffentlicht 09.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:10
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
CVE-2019-16167
- EPSS 0.24%
- Veröffentlicht 09.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:11
sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c.
CVE-2019-16168
- EPSS 0.84%
- Veröffentlicht 09.09.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:30:11
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
CVE-2019-16159
- EPSS 5.3%
- Veröffentlicht 09.09.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:30:10
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the ...
CVE-2016-10937
- EPSS 0.32%
- Veröffentlicht 08.09.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 02:45:07
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
CVE-2019-9445
- EPSS 0.06%
- Veröffentlicht 06.09.2019 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:51:39
In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.
CVE-2019-9854
- EPSS 0.76%
- Veröffentlicht 06.09.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:52:26
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...
CVE-2019-16056
- EPSS 0.58%
- Veröffentlicht 06.09.2019 18:15:15
- Zuletzt bearbeitet 21.11.2024 04:29:57
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and imple...
CVE-2019-14813
- EPSS 8.45%
- Veröffentlicht 06.09.2019 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:27:24
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...