Show filters
734 Total Results
Displaying 131-140 of 734
Sort by:
Attacker Value
Unknown
CVE-2019-19926
Disclosure Date: December 23, 2019 (last updated November 27, 2024)
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
0
Attacker Value
Unknown
CVE-2018-1311
Disclosure Date: December 18, 2019 (last updated June 22, 2024)
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
0
Attacker Value
Unknown
CVE-2019-19880
Disclosure Date: December 18, 2019 (last updated November 27, 2024)
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
0
Attacker Value
Unknown
TIBCO Spotfire Analyst and Desktop Remote Code Execution Via Shared Files
Disclosure Date: December 17, 2019 (last updated November 27, 2024)
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system. This attack is a risk only when the attacker has write access to a network file system shared with the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 7.11.1 and below, versions 7.12.0, 7.13.0, 7.14.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.3.1, and 10.3.2, versions 10.4.0, 10.5.0, and 10.6.0, TIBCO Spotfire Analytics Platform for AWS Marketplace: version 10.6.0, TIBCO Spotfire Deployment Kit: versions 7.11.1 and below, TIBCO Spotfire Desktop: versions 7.11.1 and below, versions 7.12.0, 7.13.…
0
Attacker Value
Unknown
CVE-2019-13736
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2019-13729
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13756
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13754
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13762
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
0
Attacker Value
Unknown
CVE-2019-13743
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.
0