CVE-2017-5332
- EPSS 0.23%
- Veröffentlicht 04.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:27:24
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
CVE-2017-5333
- EPSS 0.23%
- Veröffentlicht 04.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:27:24
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
CVE-2019-14813
- EPSS 8.45%
- Veröffentlicht 06.09.2019 14:15:15
- Zuletzt bearbeitet 21.11.2024 04:27:24
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...
CVE-2019-1125
- EPSS 13.43%
- Veröffentlicht 03.09.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:36:03
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulne...
CVE-2019-10171
- EPSS 0.34%
- Veröffentlicht 02.08.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:18:34
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
CVE-2019-10166
- EPSS 0.03%
- Veröffentlicht 02.08.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:33
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had alre...
CVE-2019-10167
- EPSS 0.05%
- Veröffentlicht 02.08.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:33
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to pro...
CVE-2019-10168
- EPSS 0.06%
- Veröffentlicht 02.08.2019 13:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:33
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will ex...
CVE-2019-10182
- EPSS 1.43%
- Veröffentlicht 31.07.2019 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:36
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbi...
CVE-2018-16871
- EPSS 1.53%
- Veröffentlicht 30.07.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 03:53:29
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence....