Show filters
205 Total Results
Displaying 31-40 of 205
Sort by:
Attacker Value
Unknown

CVE-2020-12460

Disclosure Date: July 27, 2020 (last updated February 21, 2025)
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its PREV_INUSE flag.
Attacker Value
Unknown

CVE-2015-9542

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
Attacker Value
Unknown

CVE-2019-15606

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
Attacker Value
Unknown

CVE-2019-15604

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
Attacker Value
Unknown

CVE-2019-19950

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
Attacker Value
Unknown

CVE-2019-19953

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Attacker Value
Unknown

CVE-2019-19951

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Attacker Value
Unknown

CVE-2019-16378

Disclosure Date: September 17, 2019 (last updated November 08, 2023)
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
Attacker Value
Unknown

CVE-2019-10086

Disclosure Date: August 20, 2019 (last updated November 08, 2023)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Attacker Value
Unknown

CVE-2018-20184

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.
0