CVE-2012-4384
- EPSS 0.45%
- Veröffentlicht 13.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 01:42:46
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
CVE-2019-18397
- EPSS 0.81%
- Veröffentlicht 13.11.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:12
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user...
CVE-2010-3440
- EPSS 0.07%
- Veröffentlicht 12.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:44
babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
CVE-2010-3844
- EPSS 0.53%
- Veröffentlicht 12.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:19:44
An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.
CVE-2010-3299
- EPSS 0.15%
- Veröffentlicht 12.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:27
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
CVE-2010-3438
- EPSS 0.53%
- Veröffentlicht 12.11.2019 20:15:09
- Zuletzt bearbeitet 21.11.2024 01:18:44
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disc...
CVE-2010-3439
- EPSS 0.57%
- Veröffentlicht 12.11.2019 20:15:09
- Zuletzt bearbeitet 21.11.2024 01:18:44
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
CVE-2010-3359
- EPSS 0.13%
- Veröffentlicht 12.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:34
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked libgarglk.so and gain access t...
CVE-2012-1572
- EPSS 0.42%
- Veröffentlicht 12.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 01:37:14
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
CVE-2011-3618
- EPSS 0.11%
- Veröffentlicht 12.11.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:30:51
atop: symlink attack possible due to insecure tempfile handling