Show filters
548 Total Results
Displaying 261-270 of 548
Sort by:
Attacker Value
Unknown

CVE-2019-12523

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost.
Attacker Value
Unknown

CVE-2019-18676

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach the proxy port can trivially perform the attack via a crafted URI scheme.
Attacker Value
Unknown

CVE-2019-18677

Disclosure Date: November 26, 2019 (last updated November 08, 2023)
An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.
Attacker Value
Unknown

CVE-2019-19221

Disclosure Date: November 21, 2019 (last updated November 08, 2023)
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
Attacker Value
Unknown

CVE-2012-4524

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
xlockmore before 5.43 'dclock' security bypass vulnerability
Attacker Value
Unknown

CVE-2019-19126

Disclosure Date: November 19, 2019 (last updated November 08, 2023)
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
Attacker Value
Unknown

CVE-2019-19062

Disclosure Date: November 18, 2019 (last updated November 08, 2023)
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
Attacker Value
Unknown

CVE-2019-19066

Disclosure Date: November 18, 2019 (last updated November 08, 2023)
A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
Attacker Value
Unknown

CVE-2019-19063

Disclosure Date: November 18, 2019 (last updated November 08, 2023)
Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.
Attacker Value
Unknown

CVE-2019-19058

Disclosure Date: November 18, 2019 (last updated November 08, 2023)
A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.