Show filters
612 Total Results
Displaying 131-140 of 612
Sort by:
Attacker Value
Unknown

CVE-2019-15604

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
Attacker Value
Unknown

CVE-2014-0175

Disclosure Date: December 13, 2019 (last updated November 27, 2024)
mcollective has a default password set at install
Attacker Value
Unknown

CVE-2019-19333

Disclosure Date: December 06, 2019 (last updated November 08, 2023)
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.
Attacker Value
Unknown

CVE-2019-19334

Disclosure Date: December 06, 2019 (last updated November 08, 2023)
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.
Attacker Value
Unknown

CVE-2015-1855

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Attacker Value
Unknown

CVE-2015-5694

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
Designate does not enforce the DNS protocol limit concerning record set sizes
Attacker Value
Unknown

CVE-2019-5087

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to corrupt memory and eventually execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.
Attacker Value
Unknown

CVE-2019-5086

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that could be exploited to corrupt memory and execute arbitrary code. In order to trigger this vulnerability, a victim would need to open a specially crafted XCF file.
Attacker Value
Unknown

CVE-2007-5743

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Attacker Value
Unknown

CVE-2013-5123

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.