Show filters
213 Total Results
Displaying 91-100 of 213
Sort by:
Attacker Value
Unknown

CVE-2019-0217

Disclosure Date: April 08, 2019 (last updated November 08, 2023)
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
Attacker Value
Unknown

ClamAV OLE2 File Out-Of-Bounds Write Vulnerability

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a lack of proper input and validation checking mechanisms for OLE2 files sent an affected device. An attacker could exploit this vulnerability by sending malformed OLE2 files to the device running an affected version ClamAV Software. An exploit could allow the attacker to cause an out-of-bounds write condition, resulting in a crash that could result in a denial of service condition on an affected device.
Attacker Value
Unknown

CVE-2019-11005

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.
0
Attacker Value
Unknown

CVE-2019-11008

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
Attacker Value
Unknown

CVE-2019-11007

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
Attacker Value
Unknown

CVE-2019-11009

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.
0
Attacker Value
Unknown

CVE-2019-11006

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.
0
Attacker Value
Unknown

Clam AntiVirus PDF Denial of Service Vulnerability

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of proper data handling mechanisms within the device buffer while indexing remaining file data on an affected device. An attacker could exploit this vulnerability by sending crafted PDF files to an affected device. A successful exploit could allow the attacker to cause a heap buffer out-of-bounds read condition, resulting in a crash that could result in a denial of service condition on an affected device.
Attacker Value
Unknown

CVE-2019-11010

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
0
Attacker Value
Unknown

CVE-2019-10906

Disclosure Date: April 07, 2019 (last updated November 08, 2023)
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.