CVE-2019-19648
- EPSS 0.56%
- Veröffentlicht 09.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:07
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or...
CVE-2019-19630
- EPSS 0.54%
- Veröffentlicht 08.12.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:05
HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.
CVE-2019-1551
- EPSS 4.53%
- Veröffentlicht 06.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:36:48
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this d...
CVE-2012-2130
- EPSS 0.07%
- Veröffentlicht 06.12.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 01:38:33
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
CVE-2019-5544
- EPSS 93.04%
- Veröffentlicht 06.12.2019 16:15:11
- Zuletzt bearbeitet 07.02.2025 14:59:31
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVE-2012-1615
- EPSS 0.1%
- Veröffentlicht 06.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 01:37:19
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
CVE-2019-19334
- EPSS 0.78%
- Veröffentlicht 06.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:35
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this fl...
CVE-2012-1114
- EPSS 0.84%
- Veröffentlicht 05.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:36:27
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
CVE-2012-1115
- EPSS 0.84%
- Veröffentlicht 05.12.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:36:28
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
CVE-2012-1105
- EPSS 0.15%
- Veröffentlicht 05.12.2019 19:15:15
- Zuletzt bearbeitet 21.11.2024 01:36:26
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.