CVE-2019-15587
- EPSS 3.03%
- Veröffentlicht 22.10.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:04
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVE-2019-17498
- EPSS 2.2%
- Veröffentlicht 21.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:22
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be ...
CVE-2019-18218
- EPSS 0.23%
- Veröffentlicht 21.10.2019 05:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:51
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
CVE-2019-18197
- EPSS 4.77%
- Veröffentlicht 18.10.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:48
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be...
- EPSS 85.81%
- Veröffentlicht 17.10.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:26:22
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !r...
CVE-2019-17672
- EPSS 5.35%
- Veröffentlicht 17.10.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17673
- EPSS 3.57%
- Veröffentlicht 17.10.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVE-2019-17674
- EPSS 2.48%
- Veröffentlicht 17.10.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:45
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17675
- EPSS 0.92%
- Veröffentlicht 17.10.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:45
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVE-2019-17669
- EPSS 8.38%
- Veröffentlicht 17.10.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:44
WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters.