CVE-2019-0211
- EPSS 85.73%
- Veröffentlicht 08.04.2019 22:29:00
- Zuletzt bearbeitet 04.04.2025 15:34:11
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with...
CVE-2019-0217
- EPSS 34.78%
- Veröffentlicht 08.04.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:30
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictio...
CVE-2019-0215
- EPSS 8.97%
- Veröffentlicht 08.04.2019 20:29:10
- Zuletzt bearbeitet 21.11.2024 04:16:30
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
CVE-2019-10740
- EPSS 0.08%
- Veröffentlicht 07.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:19:49
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This ...
CVE-2019-10906
- EPSS 2.62%
- Veröffentlicht 07.04.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:06
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVE-2019-3886
- EPSS 0.53%
- Veröffentlicht 04.04.2019 16:29:03
- Zuletzt bearbeitet 21.11.2024 04:42:47
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causi...
CVE-2019-3836
- EPSS 0.37%
- Veröffentlicht 01.04.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:39
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
CVE-2018-12545
- EPSS 6.28%
- Veröffentlicht 27.03.2019 20:29:03
- Zuletzt bearbeitet 21.11.2024 03:45:24
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to th...
CVE-2019-0160
- EPSS 0.33%
- Veröffentlicht 27.03.2019 20:29:03
- Zuletzt bearbeitet 21.11.2024 04:16:22
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
CVE-2019-3829
- EPSS 2.12%
- Veröffentlicht 27.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:37
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is...