CVE-2017-5332
- EPSS 0.23%
- Published 04.11.2019 21:15:11
- Last modified 21.11.2024 03:27:24
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
CVE-2017-5333
- EPSS 0.23%
- Published 04.11.2019 21:15:11
- Last modified 21.11.2024 03:27:24
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
CVE-2019-14813
- EPSS 8.45%
- Published 06.09.2019 14:15:15
- Last modified 21.11.2024 04:27:24
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...
CVE-2019-1125
- EPSS 13.43%
- Published 03.09.2019 18:15:12
- Last modified 21.11.2024 04:36:03
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulne...
CVE-2019-10171
- EPSS 0.34%
- Published 02.08.2019 14:15:14
- Last modified 21.11.2024 04:18:34
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
CVE-2019-10166
- EPSS 0.03%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had alre...
CVE-2019-10167
- EPSS 0.05%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to pro...
CVE-2019-10168
- EPSS 0.06%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will ex...
CVE-2019-10182
- EPSS 1.43%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbi...
CVE-2018-16871
- EPSS 1.53%
- Published 30.07.2019 17:15:12
- Last modified 21.11.2024 03:53:29
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence....