Show filters
425 Total Results
Displaying 21-30 of 425
Sort by:
Attacker Value
Unknown
CVE-2019-13241
Disclosure Date: July 04, 2019 (last updated November 27, 2024)
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
0
Attacker Value
Unknown
CVE-2019-12781
Disclosure Date: July 01, 2019 (last updated November 08, 2023)
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and the proxy connects to Django via HTTPS. In other words, django.http.HttpRequest.scheme has incorrect behavior when a client uses HTTP.
0
Attacker Value
Unknown
CVE-2019-13114
Disclosure Date: June 30, 2019 (last updated November 08, 2023)
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
0
Attacker Value
Unknown
CVE-2019-13110
Disclosure Date: June 30, 2019 (last updated November 08, 2023)
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
0
Attacker Value
Unknown
CVE-2019-13112
Disclosure Date: June 30, 2019 (last updated November 08, 2023)
A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
0
Attacker Value
Unknown
CVE-2019-13113
Disclosure Date: June 30, 2019 (last updated November 08, 2023)
Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
0
Attacker Value
Unknown
CVE-2019-13038
Disclosure Date: June 29, 2019 (last updated November 08, 2023)
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
0
Attacker Value
Unknown
CVE-2019-12817
Disclosure Date: June 25, 2019 (last updated November 08, 2023)
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.
0
Attacker Value
Unknown
CVE-2018-20843
Disclosure Date: June 24, 2019 (last updated November 08, 2023)
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
0
Attacker Value
Unknown
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
Disclosure Date: June 19, 2019 (last updated February 28, 2024)
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit 3b4929f65b0d8249f19a50245cd88ed1a2f78cff.
0