Show filters
260 Total Results
Displaying 101-110 of 260
Sort by:
Attacker Value
Unknown

CVE-2019-15604

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
Attacker Value
Unknown

CVE-2014-0175

Disclosure Date: December 13, 2019 (last updated November 27, 2024)
mcollective has a default password set at install
Attacker Value
Unknown

CVE-2015-1855

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Attacker Value
Unknown

CVE-2015-5694

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
Designate does not enforce the DNS protocol limit concerning record set sizes
Attacker Value
Unknown

CVE-2019-5087

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to corrupt memory and eventually execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.
Attacker Value
Unknown

CVE-2019-5086

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.
Attacker Value
Unknown

CVE-2007-5743

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Attacker Value
Unknown

CVE-2013-5123

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
Attacker Value
Unknown

CVE-2019-17596

Disclosure Date: October 24, 2019 (last updated November 08, 2023)
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Attacker Value
Unknown

CVE-2019-16276

Disclosure Date: September 30, 2019 (last updated November 08, 2023)
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.