CVE-2019-14835
- EPSS 0.05%
- Published 17.09.2019 16:15:10
- Last modified 21.11.2024 04:27:27
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descript...
CVE-2019-15030
- EPSS 0.07%
- Published 13.09.2019 13:15:11
- Last modified 21.11.2024 04:27:54
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transa...
CVE-2019-15031
- EPSS 0.07%
- Published 13.09.2019 13:15:11
- Last modified 21.11.2024 04:27:54
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instr...
CVE-2019-16231
- EPSS 0.04%
- Published 11.09.2019 16:15:11
- Last modified 21.11.2024 04:30:19
drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233
- EPSS 0.09%
- Published 11.09.2019 16:15:11
- Last modified 21.11.2024 04:30:20
drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16229
- EPSS 0.03%
- Published 11.09.2019 16:15:10
- Last modified 21.11.2024 04:30:19
drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deservin...
CVE-2019-9854
- EPSS 0.76%
- Published 06.09.2019 19:15:11
- Last modified 21.11.2024 04:52:26
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...
CVE-2019-14813
- EPSS 8.45%
- Published 06.09.2019 14:15:15
- Last modified 21.11.2024 04:27:24
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...
CVE-2019-15718
- EPSS 0.11%
- Published 04.09.2019 12:15:11
- Last modified 21.11.2024 04:29:19
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivile...
CVE-2019-15807
- EPSS 0.09%
- Published 29.08.2019 18:15:12
- Last modified 21.11.2024 04:29:30
In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service.