CVE-2019-5087
- EPSS 0.19%
- Veröffentlicht 21.11.2019 16:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:19
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to cor...
CVE-2019-5086
- EPSS 0.2%
- Veröffentlicht 21.11.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:44:19
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt mem...
CVE-2014-1936
- EPSS 0.43%
- Veröffentlicht 21.11.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 02:05:18
rc before 1.7.1-5 insecurely creates temporary files.
CVE-2014-1935
- EPSS 0.47%
- Veröffentlicht 21.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:05:18
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
CVE-2014-0083
- EPSS 0.07%
- Veröffentlicht 21.11.2019 14:15:13
- Zuletzt bearbeitet 21.11.2024 02:01:19
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.
CVE-2012-2350
- EPSS 0.43%
- Veröffentlicht 21.11.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 01:38:55
pam_shield before 0.9.4: Default configuration does not perform protective action
CVE-2012-3543
- EPSS 1.01%
- Veröffentlicht 21.11.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 01:41:05
mono 2.10.x ASP.NET Web Form Hash collision DoS
CVE-2019-19039
- EPSS 0.43%
- Veröffentlicht 21.11.2019 02:15:23
- Zuletzt bearbeitet 21.11.2024 04:34:02
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: ...
CVE-2015-3166
- EPSS 2.19%
- Veröffentlicht 20.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 02:28:48
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have ...
CVE-2015-3167
- EPSS 2.52%
- Veröffentlicht 20.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 02:28:48
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via...