CVE-2019-13115
- EPSS 42.82%
- Veröffentlicht 16.07.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:13
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH serve...
CVE-2019-13616
- EPSS 6.36%
- Veröffentlicht 16.07.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:22
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
CVE-2019-1010057
- EPSS 0.63%
- Veröffentlicht 16.07.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:17:56
nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdum...
CVE-2019-1010301
- EPSS 0.11%
- Veröffentlicht 15.07.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:08
jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.
CVE-2019-1010302
- EPSS 0.09%
- Veröffentlicht 15.07.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:08
jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.
CVE-2019-1010305
- EPSS 0.59%
- Veröffentlicht 15.07.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:08
libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim must open a specially crafted chm...
CVE-2019-1010006
- EPSS 0.53%
- Veröffentlicht 15.07.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:17:54
Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer ov...
CVE-2019-13602
- EPSS 0.55%
- Veröffentlicht 14.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:19
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact...
CVE-2019-13161
- EPSS 2.17%
- Veröffentlicht 12.07.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:19
An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, and Certified Asterisk through 13.21-cert3. A pointer dereference in chan_sip while handling SDP negotiation allows an attacker to...
CVE-2019-13574
- EPSS 29.49%
- Veröffentlicht 12.07.2019 03:15:10
- Zuletzt bearbeitet 21.11.2024 04:25:13
In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.