CVE-2019-11135
- EPSS 0.24%
- Veröffentlicht 14.11.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:20:35
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2019-0155
- EPSS 0.09%
- Veröffentlicht 14.11.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:16:21
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G390...
CVE-2017-5332
- EPSS 0.23%
- Veröffentlicht 04.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:27:24
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
CVE-2017-5333
- EPSS 0.23%
- Veröffentlicht 04.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 03:27:24
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
CVE-2019-6470
- EPSS 0.27%
- Veröffentlicht 01.11.2019 23:15:10
- Zuletzt bearbeitet 11.04.2025 14:55:14
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function...
CVE-2019-5010
- EPSS 3.67%
- Veröffentlicht 31.10.2019 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:44:10
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can ini...
CVE-2019-11043
- EPSS 94.11%
- Veröffentlicht 28.10.2019 15:15:13
- Zuletzt bearbeitet 14.02.2025 16:43:36
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the p...
- EPSS 86.13%
- Veröffentlicht 17.10.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:26:22
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !r...
CVE-2019-2992
- EPSS 0.82%
- Veröffentlicht 16.10.2019 18:15:33
- Zuletzt bearbeitet 21.11.2024 04:41:56
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticate...
CVE-2019-2999
- EPSS 2.66%
- Veröffentlicht 16.10.2019 18:15:33
- Zuletzt bearbeitet 21.11.2024 04:41:57
Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via mul...