CVE-2019-15143
- EPSS 0.07%
- Published 18.08.2019 19:15:09
- Last modified 21.11.2024 04:28:09
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/...
CVE-2019-15144
- EPSS 0.06%
- Published 18.08.2019 19:15:09
- Last modified 21.11.2024 04:28:09
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h...
CVE-2019-9850
- EPSS 2.71%
- Published 15.08.2019 22:15:22
- Last modified 21.11.2024 04:52:26
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...
CVE-2019-9851
- EPSS 85.95%
- Published 15.08.2019 22:15:22
- Last modified 21.11.2024 04:52:26
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calli...
CVE-2019-9852
- EPSS 0.11%
- Published 15.08.2019 22:15:22
- Last modified 21.11.2024 04:52:26
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...
CVE-2019-13377
- EPSS 1.27%
- Published 15.08.2019 17:15:13
- Last modified 21.11.2024 04:24:49
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able...
CVE-2019-12854
- EPSS 44.49%
- Published 15.08.2019 17:15:12
- Last modified 21.11.2024 04:23:43
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clien...
CVE-2019-14973
- EPSS 0.97%
- Published 14.08.2019 06:15:10
- Last modified 21.11.2024 04:27:48
_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application cras...
CVE-2019-9518
- EPSS 3.67%
- Published 13.08.2019 21:15:13
- Last modified 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONT...
CVE-2019-9511
- EPSS 13.95%
- Published 13.08.2019 21:15:12
- Last modified 14.01.2025 19:29:55
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. T...