Количество 18 769
Количество 18 769
CVE-2019-9070
CVE-2019-8457
CVE-2019-7317
CVE-2019-7309
CVE-2019-6706
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
CVE-2019-6488
CVE-2019-6486
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
CVE-2019-6470
CVE-2019-6462
CVE-2019-6461
CVE-2019-6454
CVE-2019-6293
CVE-2019-6292
An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap HandleMap HandleFlowSequence HandleSequence HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.
CVE-2019-6290
An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file.
CVE-2019-6285
The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
CVE-2019-5737
In Node.js including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1 an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121 addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1.
CVE-2019-5736
CVE-2019-5544
CVE-2019-5188
CVE-2019-5094
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 9.8 | 27% Средний | больше 1 года назад | ||
CVSS3: 5.3 | 1% Низкий | 11 месяцев назад | ||
CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | ||
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | ||
CVE-2019-6486 Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks. | 2% Низкий | 5 месяцев назад | ||
CVSS3: 7.5 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 6.5 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 6.5 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 5.5 | 0% Низкий | больше 5 лет назад | ||
CVE-2019-6292 An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap HandleMap HandleFlowSequence HandleSequence HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2019-6290 An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file. | 0% Низкий | 5 месяцев назад | ||
CVE-2019-6285 The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. | CVSS3: 6.5 | 1% Низкий | больше 5 лет назад | |
CVE-2019-5737 In Node.js including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1 an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121 addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1. | CVSS3: 7.5 | 36% Средний | больше 4 лет назад | |
CVSS3: 8.6 | 56% Средний | больше 4 лет назад | ||
CVSS3: 9.8 | 93% Критический | около 4 лет назад | ||
CVSS3: 6.7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 6.7 | 0% Низкий | около 5 лет назад |
Уязвимостей на страницу