CVE-2019-18345
- EPSS 1.09%
- Veröffentlicht 12.12.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:33:05
A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in t...
CVE-2019-19725
- EPSS 0.96%
- Veröffentlicht 11.12.2019 18:16:20
- Zuletzt bearbeitet 21.11.2024 04:35:15
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
CVE-2019-19583
- EPSS 2.07%
- Veröffentlicht 11.12.2019 18:16:19
- Zuletzt bearbeitet 21.11.2024 04:34:59
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA...
CVE-2013-7371
- EPSS 0.58%
- Veröffentlicht 11.12.2019 15:15:13
- Zuletzt bearbeitet 21.11.2024 02:00:51
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
CVE-2013-4245
- EPSS 0.15%
- Veröffentlicht 11.12.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 01:55:12
Orca has arbitrary code execution due to insecure Python module load
CVE-2013-7370
- EPSS 1.08%
- Veröffentlicht 11.12.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 02:00:51
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
CVE-2013-4158
- EPSS 0.63%
- Veröffentlicht 11.12.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:59
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
CVE-2019-19709
- EPSS 0.32%
- Veröffentlicht 11.12.2019 02:15:14
- Zuletzt bearbeitet 21.11.2024 04:35:14
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that...
CVE-2019-5815
- EPSS 0.11%
- Veröffentlicht 11.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:45:33
Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted XML data.
CVE-2019-19604
- EPSS 1.34%
- Veröffentlicht 11.12.2019 00:15:13
- Zuletzt bearbeitet 21.11.2024 04:35:02
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a ma...