CVE-2019-8308
- EPSS 0.07%
- Published 12.02.2019 23:29:00
- Last modified 21.11.2024 04:49:39
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
CVE-2019-7664
- EPSS 0.37%
- Published 09.02.2019 16:29:00
- Last modified 21.11.2024 04:48:29
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
CVE-2019-7665
- EPSS 0.14%
- Published 09.02.2019 16:29:00
- Last modified 21.11.2024 04:48:29
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does n...
CVE-2019-7548
- EPSS 1.11%
- Published 06.02.2019 21:29:01
- Last modified 21.11.2024 04:48:18
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
CVE-2018-18500
- EPSS 30.24%
- Published 05.02.2019 21:29:00
- Last modified 21.11.2024 03:56:03
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affec...
CVE-2018-18501
- EPSS 4.73%
- Published 05.02.2019 21:29:00
- Last modified 21.11.2024 03:56:03
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to r...
- EPSS 5.06%
- Published 05.02.2019 21:29:00
- Last modified 21.11.2024 03:56:04
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created...
CVE-2018-18506
- EPSS 2.44%
- Published 05.02.2019 21:29:00
- Last modified 21.11.2024 03:56:04
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This b...
CVE-2019-3813
- EPSS 0.26%
- Published 04.02.2019 18:29:00
- Last modified 21.11.2024 04:42:35
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
CVE-2019-7310
- EPSS 0.31%
- Published 03.02.2019 03:29:00
- Last modified 21.11.2024 04:47:58
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a c...