CVE-2019-6251
- EPSS 2.45%
- Veröffentlicht 14.01.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:18
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 ...
CVE-2019-3498
- EPSS 1.94%
- Veröffentlicht 09.01.2019 23:29:05
- Zuletzt bearbeitet 21.11.2024 04:42:08
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing ...
CVE-2018-20662
- EPSS 0.59%
- Veröffentlicht 03.01.2019 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:57
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is m...
CVE-2019-3500
- EPSS 0.11%
- Veröffentlicht 02.01.2019 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:08
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
CVE-2018-20592
- EPSS 0.34%
- Veröffentlicht 30.12.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:48
In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc.
CVE-2018-20593
- EPSS 0.24%
- Veröffentlicht 30.12.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:48
In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c.
CVE-2018-20549
- EPSS 0.79%
- Veröffentlicht 28.12.2018 16:29:05
- Zuletzt bearbeitet 21.11.2024 04:01:42
There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19.
CVE-2018-20545
- EPSS 1.64%
- Veröffentlicht 28.12.2018 16:29:04
- Zuletzt bearbeitet 21.11.2024 04:01:41
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
CVE-2018-20546
- EPSS 2.29%
- Veröffentlicht 28.12.2018 16:29:04
- Zuletzt bearbeitet 21.11.2024 04:01:42
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case.
CVE-2018-20547
- EPSS 0.86%
- Veröffentlicht 28.12.2018 16:29:04
- Zuletzt bearbeitet 21.11.2024 04:01:42
There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.