Show filters
252 Total Results
Displaying 61-70 of 252
Sort by:
Attacker Value
Unknown
CVE-2019-20053
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
0
Attacker Value
Unknown
CVE-2019-18389
Disclosure Date: December 23, 2019 (last updated November 27, 2024)
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
0
Attacker Value
Unknown
CVE-2019-18388
Disclosure Date: December 23, 2019 (last updated November 27, 2024)
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
0
Attacker Value
Unknown
CVE-2019-18390
Disclosure Date: December 23, 2019 (last updated November 27, 2024)
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
0
Attacker Value
Unknown
CVE-2019-19917
Disclosure Date: December 20, 2019 (last updated November 08, 2023)
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
0
Attacker Value
Unknown
CVE-2019-19918
Disclosure Date: December 20, 2019 (last updated November 08, 2023)
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
0
Attacker Value
Unknown
CVE-2019-16779
Disclosure Date: December 16, 2019 (last updated November 27, 2024)
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be short, and it would be difficult to purposefully exploit this.
0
Attacker Value
Unknown
CVE-2014-2387
Disclosure Date: December 13, 2019 (last updated November 27, 2024)
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities
0
Attacker Value
Unknown
CVE-2012-6655
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
0
Attacker Value
Unknown
CVE-2019-10214
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
0