CVE-2019-18888
- EPSS 2.74%
- Veröffentlicht 21.11.2019 23:15:13
- Zuletzt bearbeitet 21.11.2024 04:33:47
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary argu...
CVE-2019-18889
- EPSS 2.55%
- Veröffentlicht 21.11.2019 23:15:13
- Zuletzt bearbeitet 21.11.2024 04:33:47
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
CVE-2019-19221
- EPSS 0.07%
- Veröffentlicht 21.11.2019 23:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:21
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
CVE-2019-19203
- EPSS 0.73%
- Veröffentlicht 21.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:19
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read...
CVE-2019-19204
- EPSS 8.95%
- Veröffentlicht 21.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:19
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
CVE-2015-2793
- EPSS 1.29%
- Veröffentlicht 21.11.2019 20:15:15
- Zuletzt bearbeitet 21.11.2024 02:28:05
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.
CVE-2012-4524
- EPSS 0.67%
- Veröffentlicht 21.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:43:03
xlockmore before 5.43 'dclock' security bypass vulnerability
CVE-2013-1817
- EPSS 1.55%
- Veröffentlicht 20.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 01:50:26
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
CVE-2013-1816
- EPSS 4.1%
- Veröffentlicht 20.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:26
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
CVE-2012-6136
- EPSS 0.03%
- Veröffentlicht 20.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:53
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.