CVE-2018-17937
- EPSS 3.15%
- Veröffentlicht 13.03.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:14
gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON i...
CVE-2019-9741
- EPSS 3.34%
- Veröffentlicht 13.03.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:12
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
CVE-2019-9735
- EPSS 1.89%
- Veröffentlicht 13.03.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:12
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't supp...
CVE-2019-9718
- EPSS 1.6%
- Veröffentlicht 12.03.2019 09:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:10
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
CVE-2019-9704
- EPSS 0.16%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
CVE-2019-9705
- EPSS 0.16%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
CVE-2019-9706
- EPSS 0.05%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.
CVE-2019-9656
- EPSS 0.89%
- Veröffentlicht 11.03.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:03
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.
CVE-2019-9658
- EPSS 3.68%
- Veröffentlicht 11.03.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:04
Checkstyle before 8.18 loads external DTDs by default.
CVE-2019-9637
- EPSS 9.87%
- Veröffentlicht 09.03.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:01
An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() across filesystems is implemented, it is possible that file being renamed is briefly available with wrong permissions while the rename ...