Show filters
655 Total Results
Displaying 11-20 of 655
Sort by:
Attacker Value
Unknown
CVE-2013-2016
Disclosure Date: December 30, 2019 (last updated November 27, 2024)
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.
0
Attacker Value
Unknown
CVE-2019-13730
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-9811
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
0
Attacker Value
Unknown
CVE-2019-11717
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
0
Attacker Value
Unknown
CVE-2019-11338
Disclosure Date: April 19, 2019 (last updated November 27, 2024)
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
0
Attacker Value
Unknown
existing connection is being used even though eDirectory LDAP server is upgrad…
Disclosure Date: March 02, 2018 (last updated November 08, 2023)
The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.
0
Attacker Value
Unknown
eDirectory LDAP peer certificate validation issue
Disclosure Date: March 02, 2018 (last updated November 08, 2023)
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
0
Attacker Value
Unknown
CVE-2017-14496
Disclosure Date: October 03, 2017 (last updated November 08, 2023)
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
0
Attacker Value
Unknown
CVE-2017-14494
Disclosure Date: October 03, 2017 (last updated November 08, 2023)
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
0
Attacker Value
Unknown
CVE-2017-13704
Disclosure Date: October 03, 2017 (last updated November 08, 2023)
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
0