CVE-2012-4451
- EPSS 1.78%
- Veröffentlicht 03.01.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 01:42:55
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Dec...
CVE-2020-5310
- EPSS 0.61%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
CVE-2020-5311
- EPSS 1.3%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
CVE-2020-5312
- EPSS 1.73%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
CVE-2020-5313
- EPSS 0.55%
- Veröffentlicht 03.01.2020 01:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:53
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
CVE-2013-4752
- EPSS 0.93%
- Veröffentlicht 02.01.2020 17:15:10
- Zuletzt bearbeitet 21.11.2024 01:56:18
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote a...
CVE-2013-4161
- EPSS 0.05%
- Veröffentlicht 31.12.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:54:59
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
CVE-2013-4357
- EPSS 1.19%
- Veröffentlicht 31.12.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:25
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
CVE-2019-20176
- EPSS 10.78%
- Veröffentlicht 31.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:38:09
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CVE-2012-5474
- EPSS 0.07%
- Veröffentlicht 30.12.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 01:44:43
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.