CVE-2019-18792
- EPSS 0.18%
- Veröffentlicht 06.01.2020 18:15:23
- Zuletzt bearbeitet 21.11.2024 04:33:34
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The PUSH ACK pac...
CVE-2019-19911
- EPSS 0.97%
- Veröffentlicht 05.01.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:38
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryE...
CVE-2019-20330
- EPSS 1.86%
- Veröffentlicht 03.01.2020 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:16
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2020-5311
- EPSS 1.3%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
CVE-2020-5312
- EPSS 1.73%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
CVE-2020-5313
- EPSS 0.55%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
CVE-2014-8182
- EPSS 5.15%
- Veröffentlicht 02.01.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 02:18:43
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.
CVE-2014-6275
- EPSS 0.33%
- Veröffentlicht 02.01.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 02:14:04
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages are hosted on the same server than FusionForge, it can allow users to incorrectly access on-disk priva...
CVE-2013-4532
- EPSS 0.17%
- Veröffentlicht 02.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 01:55:45
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.
CVE-2019-14864
- EPSS 1.02%
- Veröffentlicht 02.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:31
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...