Show filters
2,443 Total Results
Displaying 191-200 of 2,443
Sort by:
Attacker Value
Unknown

CVE-2019-13745

Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2019-10216

Disclosure Date: November 27, 2019 (last updated November 08, 2023)
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Attacker Value
Unknown

CVE-2019-13723

Disclosure Date: November 25, 2019 (last updated November 08, 2023)
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2012-6136

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
Attacker Value
Unknown

CVE-2019-11135

Disclosure Date: November 14, 2019 (last updated November 08, 2023)
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Attacker Value
Unknown

CVE-2014-8167

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
Attacker Value
Unknown

CVE-2019-13739

Disclosure Date: November 12, 2019 (last updated November 08, 2023)
Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
Attacker Value
Unknown

CVE-2019-13749

Disclosure Date: November 12, 2019 (last updated November 08, 2023)
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Attacker Value
Unknown

CVE-2017-5332

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
Attacker Value
Unknown

CVE-2017-5333

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.