Show filters
154 Total Results
Displaying 111-120 of 154
Sort by:
Attacker Value
Unknown
CVE-2019-19919
Disclosure Date: December 20, 2019 (last updated November 27, 2024)
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
0
Attacker Value
Unknown
CVE-2019-19646
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
0
Attacker Value
Unknown
CVE-2019-19645
Disclosure Date: December 09, 2019 (last updated November 27, 2024)
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
0
Attacker Value
Unknown
CVE-2019-1551
Disclosure Date: December 06, 2019 (last updated November 08, 2023)
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
0
Attacker Value
Unknown
CVE-2019-3982
Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types. An authenticated, remote attacker could potentially exploit this vulnerability to cause a Nessus scanner to become temporarily unresponsive.
0
Attacker Value
Unknown
CVE-2019-16168
Disclosure Date: September 09, 2019 (last updated November 08, 2023)
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
0
Attacker Value
Unknown
CVE-2019-3974
Disclosure Date: August 15, 2019 (last updated November 27, 2024)
Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwritten arbitrarily, potentially creating a denial of service condition.
0
Attacker Value
Unknown
CVE-2019-11042
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
0
Attacker Value
Unknown
CVE-2019-11041
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
0
Attacker Value
Unknown
CVE-2019-11050
Disclosure Date: July 29, 2019 (last updated November 08, 2023)
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
0