CVE-2019-15718
- EPSS 0.11%
- Published 04.09.2019 12:15:11
- Last modified 21.11.2024 04:29:19
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivile...
CVE-2019-1125
- EPSS 13.43%
- Published 03.09.2019 18:15:12
- Last modified 21.11.2024 04:36:03
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulne...
CVE-2019-10086
- EPSS 0.26%
- Published 20.08.2019 21:15:12
- Last modified 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-9506
- EPSS 3.04%
- Published 14.08.2019 17:15:11
- Last modified 21.11.2024 04:51:45
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") tha...
CVE-2019-10166
- EPSS 0.03%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had alre...
CVE-2019-10167
- EPSS 0.05%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to pro...
CVE-2019-10168
- EPSS 0.06%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will ex...
CVE-2019-10182
- EPSS 1.43%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbi...
CVE-2018-16871
- EPSS 1.53%
- Published 30.07.2019 17:15:12
- Last modified 21.11.2024 03:53:29
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence....
CVE-2019-2879
- EPSS 0.45%
- Published 23.07.2019 23:15:47
- Last modified 21.11.2024 04:41:44
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...