Vulnerabilities
Vulnerable Software
Opensuse:  Security Vulnerabilities
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
CVSS Score
7.8
EPSS Score
0.011
Published
2019-02-06
It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with physical access to a locked workstation could invoke certain keyboard shortcuts, and potentially other actions.
CVSS Score
4.8
EPSS Score
0.001
Published
2019-02-06
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
CVSS Score
5.9
EPSS Score
0.013
Published
2019-02-05
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corruption and probably even a remote code execution.
CVSS Score
9.8
EPSS Score
0.081
Published
2019-02-05
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() and results in a memory corruption and possibly even a remote code execution.
CVSS Score
9.8
EPSS Score
0.061
Published
2019-02-05
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_updates() and results in a memory corruption and probably even a remote code execution.
CVSS Score
9.8
EPSS Score
0.068
Published
2019-02-05
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and probably even a remote code execution.
CVSS Score
9.8
EPSS Score
0.068
Published
2019-02-05
rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corruption and probably even a remote code execution.
CVSS Score
9.8
EPSS Score
0.068
Published
2019-02-05
In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c.
CVSS Score
7.5
EPSS Score
0.027
Published
2019-02-05
In ImageMagick before 7.0.8-25, a memory leak exists in ReadSIXELImage in coders/sixel.c.
CVSS Score
7.5
EPSS Score
0.027
Published
2019-02-05


Contact Us

Shodan ® - All rights reserved