Show filters
561 Total Results
Displaying 291-300 of 561
Sort by:
Attacker Value
Unknown

CVE-2019-19204

Disclosure Date: November 21, 2019 (last updated November 08, 2023)
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
Attacker Value
Unknown

CVE-2013-1817

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
Attacker Value
Unknown

CVE-2013-1816

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
Attacker Value
Unknown

CVE-2012-6136

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
Attacker Value
Unknown

CVE-2014-5118

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
Attacker Value
Unknown

CVE-2019-19012

Disclosure Date: November 17, 2019 (last updated November 08, 2023)
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.
Attacker Value
Unknown

CVE-2011-2726

Disclosure Date: November 15, 2019 (last updated November 27, 2024)
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
Attacker Value
Unknown

CVE-2018-12207

Disclosure Date: November 14, 2019 (last updated November 08, 2023)
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
Attacker Value
Unknown

CVE-2019-11135

Disclosure Date: November 14, 2019 (last updated November 08, 2023)
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Attacker Value
Unknown

CVE-2012-1168

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.