CVE-2018-18898
- EPSS 1.47%
- Veröffentlicht 21.03.2019 16:00:29
- Zuletzt bearbeitet 21.11.2024 03:56:50
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
CVE-2018-12022
- EPSS 2.93%
- Veröffentlicht 21.03.2019 16:00:12
- Zuletzt bearbeitet 21.11.2024 03:44:25
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in ...
CVE-2018-12023
- EPSS 4.9%
- Veröffentlicht 21.03.2019 16:00:12
- Zuletzt bearbeitet 21.11.2024 03:44:26
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provid...
CVE-2019-3816
- EPSS 0.98%
- Veröffentlicht 14.03.2019 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:36
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a sp...
CVE-2019-3833
- EPSS 3.04%
- Veröffentlicht 14.03.2019 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:38
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request t...
CVE-2019-9741
- EPSS 3.53%
- Veröffentlicht 13.03.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:12
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
CVE-2019-9704
- EPSS 0.17%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
CVE-2019-9705
- EPSS 0.17%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
CVE-2019-9687
- EPSS 0.57%
- Veröffentlicht 11.03.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:06
PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
CVE-2019-9658
- EPSS 3.81%
- Veröffentlicht 11.03.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:04
Checkstyle before 8.18 loads external DTDs by default.