CVE-2019-19922
- EPSS 0.11%
- Veröffentlicht 22.12.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:40
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expira...
- EPSS 3.46%
- Veröffentlicht 22.12.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:39
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.
CVE-2019-16785
- EPSS 1.02%
- Veröffentlicht 20.12.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:11
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any pr...
CVE-2019-16786
- EPSS 0.9%
- Veröffentlicht 20.12.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:11
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-En...
CVE-2019-17571
- EPSS 37.54%
- Veröffentlicht 20.12.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:33
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic fo...
CVE-2012-6094
- EPSS 0.69%
- Veröffentlicht 20.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:48
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
CVE-2012-6111
- EPSS 0.39%
- Veröffentlicht 20.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:50
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
CVE-2012-3409
- EPSS 0.08%
- Veröffentlicht 20.12.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 01:40:48
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
CVE-2012-5639
- EPSS 0.45%
- Veröffentlicht 20.12.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:01
LibreOffice and OpenOffice automatically open embedded content
CVE-2015-8313
- EPSS 1.06%
- Veröffentlicht 20.12.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 02:38:16
GnuTLS incorrectly validates the first byte of padding in CBC modes