CVE-2019-13638
- EPSS 2.48%
- Veröffentlicht 26.07.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:25
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable sy...
CVE-2019-14275
- EPSS 0.12%
- Veröffentlicht 26.07.2019 04:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:21
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
- EPSS 18.89%
- Veröffentlicht 25.07.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:41
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
CVE-2019-1010174
- EPSS 13.12%
- Veröffentlicht 25.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:01
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no ...
CVE-2019-2816
- EPSS 0.26%
- Veröffentlicht 23.07.2019 23:15:43
- Zuletzt bearbeitet 21.11.2024 04:41:37
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allo...
CVE-2019-2769
- EPSS 0.65%
- Veröffentlicht 23.07.2019 23:15:40
- Zuletzt bearbeitet 21.11.2024 04:41:31
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows ...
CVE-2019-2762
- EPSS 0.77%
- Veröffentlicht 23.07.2019 23:15:39
- Zuletzt bearbeitet 21.11.2024 04:41:30
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows ...
CVE-2019-2745
- EPSS 0.08%
- Veröffentlicht 23.07.2019 23:15:38
- Zuletzt bearbeitet 21.11.2024 04:41:28
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrast...
CVE-2019-11730
- EPSS 19.71%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:21:40
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents...
CVE-2019-9811
- EPSS 0.87%
- Veröffentlicht 23.07.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:52:21
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < ...