2014-04-07 CVE-2014-0160 Heartbleed - The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug. openssl N/A
2019-03-24 CVE-2019-9960 The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path. limesurvey 9.8
2019-03-23 CVE-2019-9942 A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place. twig 3.7
2019-03-21 CVE-2019-9870 plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements. oembed 9.8
2019-03-14 CVE-2019-9787 WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php. wordpress 8.8
2019-03-05 CVE-2019-9578 In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device. libu2f\-host 7.5
2019-03-01 CVE-2019-9547 In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains. storage_performance_development_kit 5.3

1998-04-10 CVE-1999-1499 named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used. bind N/A
1998-04-08 CVE-1999-0009 Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. aix, asl_ux_4800, bind, bsd_os, dg_ux, irix, linux, netbsd, open_desktop, openlinux, solaris, sunos, unixware N/A
1998-04-08 CVE-1999-0010 Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. aix, asl_ux_4800, bind, dg_ux, linux, netbsd, open_desktop, openserver, sunos, unix, unixware N/A
1998-04-08 CVE-1999-0011 Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. aix, asl_ux_4800, bind, dg_ux, linux, netbsd, open_desktop, openserver, sunos, unix, unixware N/A
1998-04-08 CVE-1999-0190 Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. solaris, sunos N/A
1998-04-08 CVE-1999-1015 Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command. appleshare_mail_server N/A
1998-04-08 CVE-1999-1040 Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable. irix N/A