Show filters
736 Total Results
Displaying 211-220 of 736
Sort by:
Attacker Value
Unknown
CVE-2020-5313
Disclosure Date: January 03, 2020 (last updated February 21, 2025)
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
0
Attacker Value
Unknown
CVE-2019-20176
Disclosure Date: December 31, 2019 (last updated November 08, 2023)
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
0
Attacker Value
Unknown
CVE-2019-20093
Disclosure Date: December 30, 2019 (last updated November 08, 2023)
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
0
Attacker Value
Unknown
CVE-2019-20051
Disclosure Date: December 27, 2019 (last updated November 08, 2023)
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.
0
Attacker Value
Unknown
CVE-2019-20021
Disclosure Date: December 27, 2019 (last updated November 08, 2023)
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
0
Attacker Value
Unknown
CVE-2019-16789
Disclosure Date: December 26, 2019 (last updated November 08, 2023)
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in the Transfer-Encoding header would get parsed by Waitress as being a chunked request, but a front-end server would use the Content-Length instead as the Transfer-Encoding header is considered invalid due to containing invalid characters. If a front-end server does HTTP pipelining to a backend Waitress server this could lead to HTTP request splitting which may lead to potential cache poisoning or unexpected information disclosure. This issue is fixed in Waitress 1.4.1 through more strict HTTP field validation.
0
Attacker Value
Unknown
CVE-2019-19956
Disclosure Date: December 24, 2019 (last updated November 08, 2023)
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
0
Attacker Value
Unknown
CVE-2019-11046
Disclosure Date: December 23, 2019 (last updated November 08, 2023)
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are identified as numeric by the OS but aren't ASCII numbers. This can read to disclosure of the content of some memory locations.
0
Attacker Value
Unknown
CVE-2019-11045
Disclosure Date: December 23, 2019 (last updated November 08, 2023)
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
0
Attacker Value
Unknown
link() silently truncates after a null byte on Windows
Disclosure Date: December 23, 2019 (last updated November 08, 2023)
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
0