Show filters
2,221 Total Results
Displaying 201-210 of 2,221
Sort by:
Attacker Value
Unknown

CVE-2013-7325

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
Attacker Value
Unknown

CVE-2014-3591

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication.
Attacker Value
Unknown

CVE-2015-0837

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack."
Attacker Value
Unknown

CVE-2015-1855

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters.
Attacker Value
Unknown

CVE-2012-6655

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
Attacker Value
Unknown

CVE-2015-7810

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Attacker Value
Unknown

CVE-2015-3166

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
Attacker Value
Unknown

CVE-2015-3167

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
Attacker Value
Unknown

CVE-2015-1606

Disclosure Date: November 20, 2019 (last updated November 08, 2023)
The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.
Attacker Value
Unknown

CVE-2019-10172

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.