CVE-2019-14821
- EPSS 0.05%
- Published 19.09.2019 18:15:10
- Last modified 21.11.2024 04:27:25
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wher...
CVE-2019-14835
- EPSS 0.05%
- Published 17.09.2019 16:15:10
- Last modified 21.11.2024 04:27:27
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descript...
CVE-2019-14813
- EPSS 8.45%
- Published 06.09.2019 14:15:15
- Last modified 21.11.2024 04:27:24
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...
CVE-2019-1125
- EPSS 13.43%
- Published 03.09.2019 18:15:12
- Last modified 21.11.2024 04:36:03
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulne...
CVE-2019-10086
- EPSS 0.26%
- Published 20.08.2019 21:15:12
- Last modified 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-14744
- EPSS 1.31%
- Published 07.08.2019 15:15:13
- Last modified 21.11.2024 04:27:15
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated ...
CVE-2019-10166
- EPSS 0.03%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had alre...
CVE-2019-10167
- EPSS 0.05%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to pro...
CVE-2019-10168
- EPSS 0.06%
- Published 02.08.2019 13:15:12
- Last modified 21.11.2024 04:18:33
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will ex...
CVE-2019-10182
- EPSS 1.43%
- Published 31.07.2019 22:15:12
- Last modified 21.11.2024 04:18:36
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbi...