CVE-2019-19054
- EPSS 0.07%
- Veröffentlicht 18.11.2019 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:05
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42...
CVE-2019-19012
- EPSS 14.78%
- Veröffentlicht 17.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:59
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). ...
CVE-2019-19010
- EPSS 0.54%
- Veröffentlicht 16.11.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:59
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
CVE-2011-2726
- EPSS 0.38%
- Veröffentlicht 15.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 01:28:50
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory ...
CVE-2013-7087
- EPSS 0.49%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:00:19
ClamAV before 0.97.7 has WWPack corrupt heap memory
CVE-2013-7088
- EPSS 0.51%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:00:19
ClamAV before 0.97.7 has buffer overflow in the libclamav component
CVE-2013-7089
- EPSS 0.47%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:00:19
ClamAV before 0.97.7: dbg_printhex possible information leak
CVE-2014-0021
- EPSS 2.37%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:01:11
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
CVE-2019-14869
- EPSS 0.27%
- Veröffentlicht 15.11.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:32
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating ...
CVE-2019-18928
- EPSS 0.5%
- Veröffentlicht 15.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:51
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.