CVE-2019-2740
- EPSS 0.51%
- Veröffentlicht 23.07.2019 23:15:38
- Zuletzt bearbeitet 21.11.2024 04:41:27
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker...
CVE-2019-9959
- EPSS 1.49%
- Veröffentlicht 22.07.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:40
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attac...
CVE-2019-1010238
- EPSS 5.39%
- Veröffentlicht 19.07.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:04
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condit...
CVE-2019-13616
- EPSS 6.76%
- Veröffentlicht 16.07.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:22
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
CVE-2019-12527
- EPSS 15.91%
- Veröffentlicht 11.07.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:23:02
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leadin...
CVE-2019-10192
- EPSS 22.48%
- Veröffentlicht 11.07.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:37
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis...
CVE-2019-10193
- EPSS 34.53%
- Veröffentlicht 11.07.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:37
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perfo...
CVE-2019-13313
- EPSS 0.04%
- Veröffentlicht 05.07.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:41
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
- EPSS 0.07%
- Veröffentlicht 25.06.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:38
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of pow...
CVE-2019-3896
- EPSS 0.11%
- Veröffentlicht 19.06.2019 00:15:13
- Zuletzt bearbeitet 21.11.2024 04:42:49
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).