CVE-2019-3836
- EPSS 0.36%
- Veröffentlicht 01.04.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:39
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
CVE-2018-12545
- EPSS 3.03%
- Veröffentlicht 27.03.2019 20:29:03
- Zuletzt bearbeitet 21.11.2024 03:45:24
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to th...
CVE-2019-0160
- EPSS 0.28%
- Veröffentlicht 27.03.2019 20:29:03
- Zuletzt bearbeitet 21.11.2024 04:16:22
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
CVE-2019-3829
- EPSS 2.08%
- Veröffentlicht 27.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:37
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is...
CVE-2019-5418
- EPSS 94.34%
- Veröffentlicht 27.03.2019 14:29:01
- Zuletzt bearbeitet 30.10.2025 20:40:11
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
CVE-2019-5419
- EPSS 12.29%
- Veröffentlicht 27.03.2019 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:44:54
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
CVE-2019-5420
- EPSS 93.1%
- Veröffentlicht 27.03.2019 14:29:01
- Zuletzt bearbeitet 21.11.2024 04:44:54
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals t...
CVE-2019-3877
- EPSS 0.81%
- Veröffentlicht 27.03.2019 13:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:46
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forw...
CVE-2019-9917
- EPSS 1.57%
- Veröffentlicht 27.03.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:34
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
CVE-2019-6341
- EPSS 41.15%
- Veröffentlicht 26.03.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:46:26
In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) ...