CVE-2019-11474
- EPSS 2.98%
- Veröffentlicht 23.04.2019 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:21:09
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
CVE-2019-11459
- EPSS 0.44%
- Veröffentlicht 22.04.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:07
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIF...
CVE-2015-1343
- EPSS 0.18%
- Veröffentlicht 22.04.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 02:25:12
All versions of unity-scope-gdrive logs search terms to syslog.
CVE-2019-11454
- EPSS 1.12%
- Veröffentlicht 22.04.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:21:06
Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Ba...
CVE-2019-11455
- EPSS 1.77%
- Veröffentlicht 22.04.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:21:06
A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of se...
CVE-2015-1327
- EPSS 0.19%
- Veröffentlicht 22.04.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:25:10
Content Hub before version 0.0+15.04.20150331-0ubuntu1.0 DBUS API only requires a file path for a content item, it doesn't actually require the confined app have access to the file to create a transfer. This could allow a malicious application using ...
CVE-2015-1341
- EPSS 0.14%
- Veröffentlicht 22.04.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:25:12
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Apport before 2.19.2 function _python_module_path.
CVE-2019-11234
- EPSS 17.17%
- Veröffentlicht 22.04.2019 11:29:03
- Zuletzt bearbeitet 21.11.2024 04:20:46
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
CVE-2019-11235
- EPSS 4.55%
- Veröffentlicht 22.04.2019 11:29:03
- Zuletzt bearbeitet 21.11.2024 04:20:47
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar is...
CVE-2019-11338
- EPSS 1.95%
- Veröffentlicht 19.04.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:54
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via c...