Show filters
112 Total Results
Displaying 31-40 of 112
Sort by:
Attacker Value
Unknown
CVE-2019-0217
Disclosure Date: April 08, 2019 (last updated November 08, 2023)
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
0
Attacker Value
Unknown
CVE-2019-10906
Disclosure Date: April 07, 2019 (last updated November 08, 2023)
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
0
Attacker Value
Unknown
CVE-2019-3836
Disclosure Date: April 01, 2019 (last updated November 08, 2023)
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
0
Attacker Value
Unknown
CVE-2018-12545
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
0
Attacker Value
Unknown
CVE-2019-9917
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
0
Attacker Value
Unknown
CVE-2019-3856
Disclosure Date: March 25, 2019 (last updated November 08, 2023)
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
0
Attacker Value
Unknown
CVE-2019-3838
Disclosure Date: March 25, 2019 (last updated November 08, 2023)
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
0
Attacker Value
Unknown
CVE-2019-3857
Disclosure Date: March 25, 2019 (last updated November 08, 2023)
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
0
Attacker Value
Unknown
CVE-2019-3835
Disclosure Date: March 25, 2019 (last updated November 08, 2023)
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
0
Attacker Value
Unknown
CVE-2019-3855
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
0