Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 479

Количество 55 479

redhat логотип

CVE-2019-13504

около 7 лет назад

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-1349

больше 6 лет назад

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-1348

больше 6 лет назад

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2019-13456

около 7 лет назад

In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2019-13454

около 7 лет назад

ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2019-13423

около 7 лет назад

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following conditions a-c are true: a) Kibana is configured to use Single-Sign-On as authentication method, one of Kerberos, JWT, Proxy, Client certificate. b) The kibanaserver user is configured to use HTTP Basic as the authentication method. c) Search Guard is configured to use an SSO authentication domain and HTTP Basic at the same time

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2019-13422

около 7 лет назад

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2019-13421

около 7 лет назад

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-13420

около 7 лет назад

Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2019-13419

около 7 лет назад

Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2019-13418

больше 7 лет назад

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

CVSS3: 5.7
EPSS: Низкий
redhat логотип

CVE-2019-13417

около 7 лет назад

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2019-13416

около 7 лет назад

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2019-13415

около 7 лет назад

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2019-13391

около 7 лет назад

In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2019-13377

около 7 лет назад

The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2019-13345

около 7 лет назад

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

CVSS3: 4.3
EPSS: Высокий
redhat логотип

CVE-2019-13313

около 7 лет назад

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2019-13311

около 7 лет назад

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2019-13310

около 7 лет назад

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-13504

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

CVSS3: 6.5
2%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-1349

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1350, CVE-2019-1352, CVE-2019-1354, CVE-2019-1387.

CVSS3: 7.5
34%
Средний
больше 6 лет назад
redhat логотип
CVE-2019-1348

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream command feature export-marks=... and it allows overwriting arbitrary paths.

CVSS3: 3.3
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-13456

In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.

CVSS3: 5.3
2%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13454

ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.

CVSS3: 3.3
4%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13423

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user could impersonate as kibanaserver user when providing wrong credentials when all of the following conditions a-c are true: a) Kibana is configured to use Single-Sign-On as authentication method, one of Kerberos, JWT, Proxy, Client certificate. b) The kibanaserver user is configured to use HTTP Basic as the authentication method. c) Search Guard is configured to use an SSO authentication domain and HTTP Basic at the same time

CVSS3: 5.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13422

Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.

CVSS3: 5.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13421

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

CVSS3: 4.9
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13420

Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.

CVSS3: 5.9
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13419

Search Guard versions before 23.1 had an issue that for aggregations clear text values of anonymised fields were leaked.

CVSS3: 5.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13418

Search Guard versions before 24.0 had an issue that values of string arrays in documents are not properly anonymized.

CVSS3: 5.7
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-13417

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level security (FLS) is activated.

CVSS3: 4.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13416

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on the local cluster ignoring their roles on the remote cluster(s).

CVSS3: 5.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13415

Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain read access to data they are not authorized to see.

CVSS3: 4.3
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13391

In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtualPixels.

CVSS3: 4
3%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13377

The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.

CVSS3: 5.3
2%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13345

The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

CVSS3: 4.3
74%
Высокий
около 7 лет назад
redhat логотип
CVE-2019-13313

libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

CVSS3: 2.8
0%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13311

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.

CVSS3: 3.3
3%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-13310

ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.

CVSS3: 5.3
2%
Низкий
около 7 лет назад

Уязвимостей на страницу