CVE-2019-5762
- EPSS 2.54%
- Published 19.02.2019 17:29:00
- Last modified 21.11.2024 04:45:26
Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
CVE-2019-5763
- EPSS 1.66%
- Published 19.02.2019 17:29:00
- Last modified 21.11.2024 04:45:26
Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-5764
- EPSS 1.53%
- Published 19.02.2019 17:29:00
- Last modified 21.11.2024 04:45:26
Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-5765
- EPSS 0.13%
- Published 19.02.2019 17:29:00
- Last modified 21.11.2024 04:45:26
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
CVE-2019-6974
- EPSS 7.22%
- Published 15.02.2019 15:29:00
- Last modified 21.11.2024 04:47:20
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
CVE-2019-8308
- EPSS 0.07%
- Published 12.02.2019 23:29:00
- Last modified 21.11.2024 04:49:39
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.
CVE-2018-12547
- EPSS 0.83%
- Published 11.02.2019 15:29:00
- Last modified 21.11.2024 03:45:24
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly ...
CVE-2018-12549
- EPSS 0.76%
- Published 11.02.2019 15:29:00
- Last modified 21.11.2024 03:45:25
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.
CVE-2019-7664
- EPSS 0.37%
- Published 09.02.2019 16:29:00
- Last modified 21.11.2024 04:48:29
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
CVE-2019-7665
- EPSS 0.14%
- Published 09.02.2019 16:29:00
- Last modified 21.11.2024 04:48:29
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does n...