CVE-2019-1788
- EPSS 9.53%
- Veröffentlicht 08.04.2019 20:29:11
- Zuletzt bearbeitet 21.11.2024 04:37:22
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected ...
CVE-2019-11006
- EPSS 1.41%
- Veröffentlicht 08.04.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:20:20
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.
CVE-2019-11007
- EPSS 2.11%
- Veröffentlicht 08.04.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:20:20
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
CVE-2019-11008
- EPSS 2.08%
- Veröffentlicht 08.04.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:20:20
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact ...
CVE-2019-11009
- EPSS 1.33%
- Veröffentlicht 08.04.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:20:21
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
CVE-2019-11010
- EPSS 0.61%
- Veröffentlicht 08.04.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:20:21
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
CVE-2019-1787
- EPSS 5.47%
- Veröffentlicht 08.04.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:37:22
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...
CVE-2019-10732
- EPSS 0.14%
- Veröffentlicht 07.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:19:49
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipa...
CVE-2019-10904
- EPSS 0.6%
- Veröffentlicht 06.04.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:06
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
CVE-2019-10868
- EPSS 0.27%
- Veröffentlicht 05.04.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:00
In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the...