CVE-2019-19926
- EPSS 6.32%
- Veröffentlicht 23.12.2019 01:15:13
- Zuletzt bearbeitet 21.11.2024 04:35:41
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880.
CVE-2019-19922
- EPSS 0.06%
- Veröffentlicht 22.12.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:40
kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expira...
CVE-2019-19880
- EPSS 6.4%
- Veröffentlicht 18.12.2019 06:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:34
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled.
CVE-2019-19603
- EPSS 1.65%
- Veröffentlicht 09.12.2019 19:15:14
- Zuletzt bearbeitet 21.11.2024 04:35:01
SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash.
CVE-2019-19646
- EPSS 7.19%
- Veröffentlicht 09.12.2019 19:15:14
- Zuletzt bearbeitet 21.11.2024 04:35:07
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
CVE-2019-19645
- EPSS 0.3%
- Veröffentlicht 09.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:07
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
CVE-2019-19448
- EPSS 0.78%
- Veröffentlicht 08.12.2019 02:15:09
- Zuletzt bearbeitet 21.11.2024 04:34:45
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer...
CVE-2019-19447
- EPSS 1.25%
- Veröffentlicht 08.12.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:45
In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c.
CVE-2019-19317
- EPSS 0.99%
- Veröffentlicht 05.12.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 04:34:33
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2019-19377
- EPSS 0.39%
- Veröffentlicht 29.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:40
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.