CVE-2019-2503
- EPSS 0.14%
- Published 16.01.2019 19:30:34
- Last modified 21.11.2024 04:41:00
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low p...
CVE-2019-2449
- EPSS 2.56%
- Published 16.01.2019 19:30:32
- Last modified 21.11.2024 04:40:53
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protoco...
CVE-2019-2455
- EPSS 0.17%
- Published 16.01.2019 19:30:32
- Last modified 21.11.2024 04:40:54
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attac...
CVE-2019-2422
- EPSS 0.24%
- Published 16.01.2019 19:30:31
- Last modified 21.11.2024 04:40:50
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker...
CVE-2018-16886
- EPSS 0.74%
- Published 14.01.2019 19:29:00
- Last modified 21.11.2024 03:53:32
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Nam...
CVE-2018-16865
- EPSS 2.07%
- Published 11.01.2019 21:29:00
- Last modified 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remo...
CVE-2018-16864
- EPSS 0.15%
- Published 11.01.2019 20:29:00
- Last modified 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash s...
CVE-2018-16866
- EPSS 0.11%
- Published 11.01.2019 19:29:00
- Last modified 21.11.2024 03:53:28
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
CVE-2019-6133
- EPSS 0.01%
- Published 11.01.2019 14:29:00
- Last modified 21.11.2024 04:46:00
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendin...
CVE-2018-6174
- EPSS 2.02%
- Published 09.01.2019 19:29:11
- Last modified 21.11.2024 04:10:13
Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.