CVE-2019-10195
- EPSS 0.72%
- Published 27.11.2019 08:15:10
- Last modified 21.11.2024 04:18:37
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on Fre...
CVE-2019-18679
- EPSS 38.43%
- Published 26.11.2019 17:15:13
- Last modified 21.11.2024 04:33:31
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits wi...
CVE-2019-18676
- EPSS 1.37%
- Published 26.11.2019 17:15:12
- Last modified 21.11.2024 04:33:30
An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurri...
CVE-2019-18677
- EPSS 4.21%
- Published 26.11.2019 17:15:12
- Last modified 21.11.2024 04:33:30
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately ...
CVE-2019-18678
- EPSS 9.96%
- Published 26.11.2019 17:15:12
- Last modified 21.11.2024 04:33:30
An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (be...
CVE-2019-12523
- EPSS 0.56%
- Published 26.11.2019 17:15:10
- Last modified 21.11.2024 04:23:01
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...
CVE-2019-12526
- EPSS 33.64%
- Published 26.11.2019 17:15:10
- Last modified 21.11.2024 04:23:02
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...
CVE-2019-6477
- EPSS 5.71%
- Published 26.11.2019 16:15:13
- Last modified 21.11.2024 04:46:31
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resourc...
CVE-2019-19270
- EPSS 0.2%
- Published 26.11.2019 04:15:12
- Last modified 21.11.2024 04:34:27
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken in...
CVE-2019-19246
- EPSS 0.19%
- Published 25.11.2019 17:15:11
- Last modified 21.11.2024 04:34:24
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.