Show filters
112 Total Results
Displaying 51-60 of 112
Sort by:
Attacker Value
Unknown

CVE-2019-5885

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
0
Attacker Value
Unknown

CVE-2018-19872

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
0
Attacker Value
Unknown

CVE-2018-18898

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
Attacker Value
Unknown

CVE-2019-3833

Disclosure Date: March 14, 2019 (last updated November 27, 2024)
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
Attacker Value
Unknown

CVE-2019-3816

Disclosure Date: March 14, 2019 (last updated November 27, 2024)
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
Attacker Value
Unknown

CVE-2019-9658

Disclosure Date: March 11, 2019 (last updated November 08, 2023)
Checkstyle before 8.18 loads external DTDs by default.
0
Attacker Value
Unknown

CVE-2019-9636

Disclosure Date: March 08, 2019 (last updated November 08, 2023)
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.
Attacker Value
Unknown

CVE-2019-9631

Disclosure Date: March 08, 2019 (last updated November 08, 2023)
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
0
Attacker Value
Unknown

CVE-2018-14498

Disclosure Date: March 07, 2019 (last updated November 08, 2023)
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
0
Attacker Value
Unknown

CVE-2019-8377

Disclosure Date: February 17, 2019 (last updated November 08, 2023)
An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.