Show filters
111 Total Results
Displaying 11-20 of 111
Sort by:
Attacker Value
Unknown

CVE-2019-7164

Disclosure Date: February 20, 2019 (last updated November 27, 2024)
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
Attacker Value
Unknown

CVE-2019-3500

Disclosure Date: January 02, 2019 (last updated November 08, 2023)
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
Attacker Value
Unknown

CVE-2018-20189

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.
0
Attacker Value
Unknown

Information disclosure in Special:Redirect/logid

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
0
Attacker Value
Unknown

$wgRateLimits entry for 'user' overrides 'newbie'

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
0
Attacker Value
Unknown

BotPasswords can bypass CentralAuth's account lock

Disclosure Date: October 04, 2018 (last updated November 27, 2024)
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
0
Attacker Value
Unknown

CVE-2014-2079

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
0
Attacker Value
Unknown

CVE-2018-1129

Disclosure Date: July 10, 2018 (last updated November 27, 2024)
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
0
Attacker Value
Unknown

CVE-2018-1089

Disclosure Date: May 09, 2018 (last updated November 26, 2024)
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
0
Attacker Value
Unknown

CVE-2018-10392

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file.