Show filters
1,412 Total Results
Displaying 81-90 of 1,412
Sort by:
Attacker Value
Unknown

CVE-2017-5333

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
Attacker Value
Unknown

CVE-2019-18218

Disclosure Date: October 21, 2019 (last updated November 08, 2023)
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
Attacker Value
Unknown

CVE-2019-18197

Disclosure Date: October 18, 2019 (last updated November 27, 2024)
In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized data could be disclosed.
Attacker Value
Unknown

CVE-2019-17544

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
Attacker Value
Unknown

CVE-2019-15165

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
Attacker Value
Unknown

CVE-2019-15166

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
Attacker Value
Unknown

CVE-2019-16935

Disclosure Date: September 28, 2019 (last updated November 08, 2023)
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.
Attacker Value
Unknown

CVE-2019-9278

Disclosure Date: September 27, 2019 (last updated November 08, 2023)
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
Attacker Value
Unknown

CVE-2019-13627

Disclosure Date: September 25, 2019 (last updated November 27, 2024)
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
Attacker Value
Unknown

CVE-2019-5094

Disclosure Date: September 24, 2019 (last updated November 08, 2023)
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.