CVE-2019-12482
- EPSS 0.55%
- Veröffentlicht 30.05.2019 23:29:00
- Zuletzt bearbeitet 14.03.2025 19:09:03
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.
CVE-2019-12483
- EPSS 0.26%
- Veröffentlicht 30.05.2019 23:29:00
- Zuletzt bearbeitet 14.03.2025 19:09:12
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
CVE-2019-12450
- EPSS 0.94%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:52
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
CVE-2019-9858
- EPSS 80.41%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:27
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes t...
CVE-2019-5436
- EPSS 13.49%
- Veröffentlicht 28.05.2019 19:29:06
- Zuletzt bearbeitet 21.11.2024 04:44:55
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVE-2019-5798
- EPSS 1.28%
- Veröffentlicht 23.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:30
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2019-0201
- EPSS 0.22%
- Veröffentlicht 23.05.2019 14:29:07
- Zuletzt bearbeitet 21.11.2024 04:16:28
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field a...
CVE-2019-12295
- EPSS 1.43%
- Veröffentlicht 23.05.2019 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:34
In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
CVE-2019-11841
- EPSS 0.39%
- Veröffentlicht 22.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:52
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain...
CVE-2019-12046
- EPSS 0.93%
- Veröffentlicht 22.05.2019 16:29:01
- Zuletzt bearbeitet 28.05.2025 17:23:02
LemonLDAP::NG -2.0.3 has Incorrect Access Control.