CVE-2019-19054
- EPSS 0.07%
- Published 18.11.2019 06:15:11
- Last modified 21.11.2024 04:34:05
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42...
CVE-2019-19012
- EPSS 14.78%
- Published 17.11.2019 18:15:11
- Last modified 21.11.2024 04:33:59
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). ...
CVE-2019-19010
- EPSS 0.54%
- Published 16.11.2019 01:15:10
- Last modified 21.11.2024 04:33:59
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
CVE-2011-2726
- EPSS 0.38%
- Published 15.11.2019 17:15:12
- Last modified 21.11.2024 01:28:50
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory ...
CVE-2013-7087
- EPSS 0.49%
- Published 15.11.2019 15:15:11
- Last modified 21.11.2024 02:00:19
ClamAV before 0.97.7 has WWPack corrupt heap memory
CVE-2013-7088
- EPSS 0.51%
- Published 15.11.2019 15:15:11
- Last modified 21.11.2024 02:00:19
ClamAV before 0.97.7 has buffer overflow in the libclamav component
CVE-2013-7089
- EPSS 0.47%
- Published 15.11.2019 15:15:11
- Last modified 21.11.2024 02:00:19
ClamAV before 0.97.7: dbg_printhex possible information leak
CVE-2014-0021
- EPSS 2.37%
- Published 15.11.2019 15:15:11
- Last modified 21.11.2024 02:01:11
Chrony before 1.29.1 has traffic amplification in cmdmon protocol
CVE-2019-14869
- EPSS 0.27%
- Published 15.11.2019 12:15:10
- Last modified 21.11.2024 04:27:32
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating ...
CVE-2019-18928
- EPSS 0.5%
- Published 15.11.2019 04:15:10
- Last modified 21.11.2024 04:33:51
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.