CVE-2019-20161
- EPSS 0.43%
- Veröffentlicht 31.12.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:07
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.
CVE-2019-20162
- EPSS 0.43%
- Veröffentlicht 31.12.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:07
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.
CVE-2019-20163
- EPSS 0.47%
- Veröffentlicht 31.12.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:08
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.
CVE-2019-20165
- EPSS 0.47%
- Veröffentlicht 31.12.2019 00:15:12
- Zuletzt bearbeitet 21.11.2024 04:38:08
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.
CVE-2013-2016
- EPSS 0.07%
- Veröffentlicht 30.12.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:50:52
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use ...
CVE-2012-5474
- EPSS 0.07%
- Veröffentlicht 30.12.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 01:44:43
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
CVE-2012-5476
- EPSS 0.15%
- Veröffentlicht 30.12.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 01:44:43
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
CVE-2019-20096
- EPSS 0.07%
- Veröffentlicht 30.12.2019 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:03
In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-20041
- EPSS 1.37%
- Veröffentlicht 27.12.2019 08:15:09
- Zuletzt bearbeitet 21.11.2024 04:37:56
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.
CVE-2019-20042
- EPSS 5.05%
- Veröffentlicht 27.12.2019 08:15:09
- Zuletzt bearbeitet 21.11.2024 04:37:56
In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the ...