CVE-2019-2627
- EPSS 0.17%
- Published 23.04.2019 19:32:52
- Last modified 21.11.2024 04:41:14
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high p...
CVE-2019-2614
- EPSS 0.16%
- Published 23.04.2019 19:32:51
- Last modified 21.11.2024 04:41:13
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileg...
CVE-2019-2602
- EPSS 0.27%
- Published 23.04.2019 19:32:50
- Last modified 21.11.2024 04:41:11
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unau...
CVE-2019-0223
- EPSS 0.53%
- Published 23.04.2019 16:29:00
- Last modified 21.11.2024 04:16:31
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer cert...
CVE-2019-10245
- EPSS 1.62%
- Published 19.04.2019 14:29:00
- Last modified 21.11.2024 04:18:43
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
CVE-2019-3459
- EPSS 0.48%
- Published 11.04.2019 16:29:02
- Last modified 21.11.2024 04:42:05
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
CVE-2019-3460
- EPSS 0.48%
- Published 11.04.2019 16:29:02
- Last modified 21.11.2024 04:42:05
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
CVE-2019-0217
- EPSS 34.78%
- Published 08.04.2019 21:29:00
- Last modified 21.11.2024 04:16:30
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictio...
CVE-2019-3878
- EPSS 3.21%
- Published 26.03.2019 18:29:00
- Last modified 21.11.2024 04:42:46
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers tha...
CVE-2019-3835
- EPSS 1.7%
- Published 25.03.2019 19:29:01
- Last modified 21.11.2024 04:42:39
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains i...