Show filters
1,191 Total Results
Displaying 351-360 of 1,191
Sort by:
Attacker Value
Unknown

CVE-2019-19126

Disclosure Date: November 19, 2019 (last updated November 08, 2023)
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
Attacker Value
Unknown

CVE-2012-0824

Disclosure Date: November 19, 2019 (last updated November 27, 2024)
gnusound 0.7.5 has format string issue
Attacker Value
Unknown

CVE-2019-18862

Disclosure Date: November 11, 2019 (last updated November 27, 2024)
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
Attacker Value
Unknown

CVE-2002-2439

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
Attacker Value
Unknown

CVE-2019-12290

Disclosure Date: October 22, 2019 (last updated November 08, 2023)
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain punycoded Unicode characters (that would be discarded when converted first to a Unicode label and then back to an ASCII label), arbitrary domains can be impersonated.
Attacker Value
Unknown

CVE-2019-18224

Disclosure Date: October 21, 2019 (last updated November 08, 2023)
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
Attacker Value
Unknown

CVE-2019-18192

Disclosure Date: October 17, 2019 (last updated November 27, 2024)
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
Attacker Value
Unknown

CVE-2019-17594

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Attacker Value
Unknown

CVE-2019-17595

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
Attacker Value
Unknown

CVE-2019-17544

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.