- EPSS 0.74%
- Veröffentlicht 27.11.2019 09:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:38
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join...
CVE-2019-18679
- EPSS 44.13%
- Veröffentlicht 26.11.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:33:31
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits wi...
CVE-2019-18676
- EPSS 1.37%
- Veröffentlicht 26.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:30
An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurri...
CVE-2019-18677
- EPSS 4.21%
- Veröffentlicht 26.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:30
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately ...
CVE-2019-18678
- EPSS 12.53%
- Veröffentlicht 26.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:30
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (be...
CVE-2019-15845
- EPSS 0.33%
- Veröffentlicht 26.11.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:35
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
CVE-2019-12523
- EPSS 0.56%
- Veröffentlicht 26.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:01
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...
CVE-2019-12526
- EPSS 39.19%
- Veröffentlicht 26.11.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:02
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...
CVE-2019-19244
- EPSS 0.16%
- Veröffentlicht 25.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:24
sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage.
CVE-2019-19246
- EPSS 0.32%
- Veröffentlicht 25.11.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:24
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.