CVE-2019-18391
- EPSS 0.03%
- Veröffentlicht 23.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:11
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
CVE-2019-19340
- EPSS 0.41%
- Veröffentlicht 19.12.2019 21:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:36
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the defaul...
CVE-2019-19906
- EPSS 0.4%
- Veröffentlicht 19.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:37
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c ...
CVE-2019-16777
- EPSS 0.29%
- Veröffentlicht 13.12.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:10
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and cre...
CVE-2019-16775
- EPSS 0.35%
- Veröffentlicht 13.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:09
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the ...
CVE-2019-16776
- EPSS 0.4%
- Veröffentlicht 13.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:10
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field wou...
CVE-2019-13734
- EPSS 5.9%
- Veröffentlicht 10.12.2019 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:25:36
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-19333
- EPSS 0.82%
- Veröffentlicht 06.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:35
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, whi...
CVE-2019-19334
- EPSS 0.86%
- Veröffentlicht 06.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:35
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this fl...
CVE-2019-19624
- EPSS 0.23%
- Veröffentlicht 06.12.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:04
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, this is not true when dealing w...