CVE-2019-19203
- EPSS 0.73%
- Veröffentlicht 21.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:19
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to a heap-based buffer over-read...
CVE-2019-19204
- EPSS 8.95%
- Veröffentlicht 21.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:19
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
CVE-2015-2793
- EPSS 1.29%
- Veröffentlicht 21.11.2019 20:15:15
- Zuletzt bearbeitet 21.11.2024 02:28:05
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.
CVE-2012-4524
- EPSS 0.67%
- Veröffentlicht 21.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:43:03
xlockmore before 5.43 'dclock' security bypass vulnerability
CVE-2013-1817
- EPSS 1.55%
- Veröffentlicht 20.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 01:50:26
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
CVE-2013-1816
- EPSS 4.1%
- Veröffentlicht 20.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:50:26
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
CVE-2012-6136
- EPSS 0.03%
- Veröffentlicht 20.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:53
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
CVE-2019-19126
- EPSS 0.02%
- Veröffentlicht 19.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:14
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping ad...
CVE-2011-2924
- EPSS 0.13%
- Veröffentlicht 19.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:29:17
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriti...
CVE-2019-18934
- EPSS 1.23%
- Veröffentlicht 19.11.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:52
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ips...