CVE-2018-1002102
- EPSS 0.21%
- Veröffentlicht 05.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 03:40:38
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the r...
CVE-2019-19579
- EPSS 0.13%
- Veröffentlicht 04.12.2019 22:15:15
- Zuletzt bearbeitet 21.11.2024 04:34:59
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-1...
CVE-2013-4411
- EPSS 0.51%
- Veröffentlicht 03.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:55:30
Review Board: URL processing gives unauthorized users access to review lists
CVE-2013-4235
- EPSS 0.06%
- Veröffentlicht 03.12.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:11
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
CVE-2013-4410
- EPSS 0.97%
- Veröffentlicht 02.12.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 01:55:30
ReviewBoard: has an access-control problem in REST API
CVE-2012-4428
- EPSS 33.32%
- Veröffentlicht 02.12.2019 18:15:09
- Zuletzt bearbeitet 21.11.2024 01:42:52
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
CVE-2012-4480
- EPSS 0.13%
- Veröffentlicht 02.12.2019 18:15:09
- Zuletzt bearbeitet 21.11.2024 01:42:58
mom creates world-writable pid files in /var/run
CVE-2019-19118
- EPSS 0.29%
- Veröffentlicht 02.12.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:13
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, would be presen...
CVE-2019-19479
- EPSS 0.05%
- Veröffentlicht 01.12.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:48
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
CVE-2019-18609
- EPSS 2.76%
- Veröffentlicht 01.12.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:21
An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header ...