CVE-2016-5285
- EPSS 1.63%
- Veröffentlicht 15.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:53:59
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
CVE-2013-4584
- EPSS 0.58%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:55:52
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections
CVE-2013-7087
- EPSS 0.48%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:00:19
ClamAV before 0.97.7 has WWPack corrupt heap memory
CVE-2013-7088
- EPSS 0.41%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:00:19
ClamAV before 0.97.7 has buffer overflow in the libclamav component
CVE-2013-7089
- EPSS 0.46%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:00:19
ClamAV before 0.97.7: dbg_printhex possible information leak
CVE-2014-0021
- EPSS 2.37%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:01:11
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
CVE-2019-18928
- EPSS 0.39%
- Veröffentlicht 15.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:51
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
CVE-2019-18978
- EPSS 1.02%
- Veröffentlicht 14.11.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:55
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2018-12207
- EPSS 0.26%
- Veröffentlicht 14.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 03:44:45
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
CVE-2019-11135
- EPSS 0.32%
- Veröffentlicht 14.11.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:20:35
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.