CVE-2019-10746
- EPSS 0.87%
- Veröffentlicht 23.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:19:50
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
CVE-2019-10086
- EPSS 0.32%
- Veröffentlicht 20.08.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-2126
- EPSS 9.31%
- Veröffentlicht 20.08.2019 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:40:16
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat...
CVE-2019-15237
- EPSS 0.14%
- Veröffentlicht 20.08.2019 01:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:15
Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks.
CVE-2019-15151
- EPSS 0.5%
- Veröffentlicht 18.08.2019 21:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:10
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
CVE-2019-15145
- EPSS 0.23%
- Veröffentlicht 18.08.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:28:09
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a ...
CVE-2019-15142
- EPSS 0.87%
- Veröffentlicht 18.08.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:08
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
CVE-2019-15143
- EPSS 0.87%
- Veröffentlicht 18.08.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:09
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/...
CVE-2019-15144
- EPSS 0.65%
- Veröffentlicht 18.08.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:09
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h...
CVE-2019-9850
- EPSS 2.91%
- Veröffentlicht 15.08.2019 22:15:22
- Zuletzt bearbeitet 21.11.2024 04:52:26
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...