CVE-2019-19906
- EPSS 0.35%
- Veröffentlicht 19.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:37
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c ...
CVE-2018-1311
- EPSS 4.17%
- Veröffentlicht 18.12.2019 20:15:15
- Zuletzt bearbeitet 04.11.2025 19:15:38
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disabl...
CVE-2019-19880
- EPSS 6.4%
- Veröffentlicht 18.12.2019 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:34
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
CVE-2012-2237
- EPSS 6.62%
- Veröffentlicht 17.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 01:38:44
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms,...
CVE-2019-19813
- EPSS 1.25%
- Veröffentlicht 17.12.2019 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:26
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner...
CVE-2019-19816
- EPSS 1.15%
- Veröffentlicht 17.12.2019 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:26
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the number of data stripes is mishandl...
CVE-2019-19830
- EPSS 0.54%
- Veröffentlicht 17.12.2019 05:15:14
- Zuletzt bearbeitet 21.11.2024 04:35:28
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
CVE-2019-16779
- EPSS 0.56%
- Veröffentlicht 16.12.2019 20:15:15
- Zuletzt bearbeitet 21.11.2024 04:31:10
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content ...
CVE-2019-19331
- EPSS 0.49%
- Veröffentlicht 16.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:35
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such unca...
CVE-2019-19783
- EPSS 1.28%
- Veröffentlicht 16.12.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:22
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a ...