Количество 25 045
Количество 25 045
CVE-2019-17414
tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL.
CVE-2019-17402
CVE-2019-17362
In LibTomCrypt through 1.18.2 the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data.
CVE-2019-16910
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
CVE-2019-16905
CVE-2019-16884
CVE-2019-16760
Cargo prior to Rust 1.26.0 may download the wrong dependency
CVE-2019-16707
Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.
CVE-2019-16276
CVE-2019-16275
CVE-2019-16255
CVE-2019-16254
CVE-2019-16201
CVE-2019-16168
In SQLite through 3.29.0 whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field aka a "severe division by zero in the query planner."
CVE-2019-15961
CVE-2019-15903
In libexpat before 2.2.8 crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
CVE-2019-15847
CVE-2019-15845
CVE-2019-1563
Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey
CVE-2019-1551
rsaz_512_sqr overflow bug on x86_64
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-17414 tinylcy Vino through 2017-12-15 allows remote attackers to cause a denial of service ("vn_get_string error: Resource temporarily unavailable" error and daemon crash) via a long URL. | CVSS3: 7.5 | 2% Низкий | 10 месяцев назад | |
CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | ||
CVE-2019-17362 In LibTomCrypt through 1.18.2 the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from other memory locations via carefully crafted DER-encoded data. | CVSS3: 9.1 | 3% Низкий | больше 4 лет назад | |
CVE-2019-16910 Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.) | 2% Низкий | 11 месяцев назад | ||
CVSS3: 7.8 | 2% Низкий | почти 6 лет назад | ||
CVSS3: 7.5 | 4% Низкий | около 5 лет назад | ||
CVE-2019-16760 Cargo prior to Rust 1.26.0 may download the wrong dependency | 1% Низкий | 6 месяцев назад | ||
CVE-2019-16707 Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx. | CVSS3: 6.5 | 2% Низкий | 11 месяцев назад | |
CVSS3: 7.5 | 5% Низкий | почти 2 года назад | ||
CVSS3: 6.5 | 1% Низкий | почти 6 лет назад | ||
CVSS3: 8.1 | 4% Низкий | почти 6 лет назад | ||
CVSS3: 5.3 | 5% Низкий | почти 6 лет назад | ||
CVSS3: 7.5 | 5% Низкий | почти 6 лет назад | ||
CVE-2019-16168 In SQLite through 3.29.0 whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field aka a "severe division by zero in the query planner." | CVSS3: 6.5 | 4% Низкий | 6 месяцев назад | |
CVSS3: 6.5 | 3% Низкий | почти 6 лет назад | ||
CVE-2019-15903 In libexpat before 2.2.8 crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read. | CVSS3: 7.5 | 7% Низкий | больше 4 лет назад | |
CVSS3: 7.5 | 3% Низкий | почти 6 лет назад | ||
CVSS3: 6.5 | 3% Низкий | почти 6 лет назад | ||
CVE-2019-1563 Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkey | 4% Низкий | 3 месяца назад | ||
CVE-2019-1551 rsaz_512_sqr overflow bug on x86_64 | 14% Средний | 3 месяца назад |
Уязвимостей на страницу