CVE-2019-12481
- EPSS 0.27%
- Veröffentlicht 30.05.2019 23:29:00
- Zuletzt bearbeitet 14.03.2025 19:08:51
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.
CVE-2019-12482
- EPSS 0.55%
- Veröffentlicht 30.05.2019 23:29:00
- Zuletzt bearbeitet 14.03.2025 19:09:03
An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.
CVE-2019-12483
- EPSS 0.26%
- Veröffentlicht 30.05.2019 23:29:00
- Zuletzt bearbeitet 14.03.2025 19:09:12
An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.
CVE-2019-12450
- EPSS 1.38%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:52
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
CVE-2019-9858
- EPSS 79.84%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:27
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, it invokes t...
CVE-2019-5436
- EPSS 15.48%
- Veröffentlicht 28.05.2019 19:29:06
- Zuletzt bearbeitet 15.04.2026 21:17:01
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVE-2019-5798
- EPSS 1.24%
- Veröffentlicht 23.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:30
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2019-0201
- EPSS 0.21%
- Veröffentlicht 23.05.2019 14:29:07
- Zuletzt bearbeitet 21.11.2024 04:16:28
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field a...
CVE-2019-12295
- EPSS 1.4%
- Veröffentlicht 23.05.2019 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:34
In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.
CVE-2019-11841
- EPSS 0.4%
- Veröffentlicht 22.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:52
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain...