CVE-2019-13725
- EPSS 7.02%
- Published 10.12.2019 22:15:12
- Last modified 21.11.2024 04:25:35
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVE-2019-13726
- EPSS 7.4%
- Published 10.12.2019 22:15:12
- Last modified 21.11.2024 04:25:35
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVE-2019-13727
- EPSS 1.28%
- Published 10.12.2019 22:15:12
- Last modified 21.11.2024 04:25:35
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
CVE-2019-13728
- EPSS 3.15%
- Published 10.12.2019 22:15:12
- Last modified 21.11.2024 04:25:35
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-5544
- EPSS 93.04%
- Published 06.12.2019 16:15:11
- Last modified 07.02.2025 14:59:31
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVE-2019-10216
- EPSS 0.53%
- Published 27.11.2019 13:15:10
- Last modified 21.11.2024 04:18:40
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that coul...
CVE-2019-13723
- EPSS 4.73%
- Published 25.11.2019 15:15:34
- Last modified 21.11.2024 04:25:34
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
CVE-2012-6136
- EPSS 0.03%
- Published 20.11.2019 15:15:11
- Last modified 21.11.2024 01:45:53
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
CVE-2019-11135
- EPSS 0.24%
- Published 14.11.2019 19:15:13
- Last modified 21.11.2024 04:20:35
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2017-5332
- EPSS 0.23%
- Published 04.11.2019 21:15:11
- Last modified 21.11.2024 03:27:24
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.