CVE-2019-10126
- EPSS 3.84%
- Published 14.06.2019 14:29:00
- Last modified 21.11.2024 04:18:28
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.
CVE-2019-12615
- EPSS 2.03%
- Published 03.06.2019 22:29:00
- Last modified 21.11.2024 04:23:11
An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup_const of node_info->vdev_port.name, which might allow an attacker to cause a denial of service (NULL poin...
CVE-2019-3846
- EPSS 0.38%
- Published 03.06.2019 19:29:02
- Last modified 21.11.2024 04:42:41
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
CVE-2018-20839
- EPSS 0.67%
- Published 17.05.2019 04:29:00
- Last modified 05.05.2025 14:14:36
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occurs because the KDGKBMODE (aka current keyboard mo...
CVE-2019-11815
- EPSS 1.19%
- Published 08.05.2019 14:29:00
- Last modified 21.11.2024 04:21:49
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
CVE-2019-3844
- EPSS 0.16%
- Published 26.04.2019 21:29:00
- Last modified 21.11.2024 04:42:41
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker...
CVE-2019-3843
- EPSS 0.13%
- Published 26.04.2019 21:29:00
- Last modified 21.11.2024 04:42:41
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access res...
CVE-2019-3900
- EPSS 0.09%
- Published 25.04.2019 15:29:00
- Last modified 21.11.2024 04:42:49
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest ...
CVE-2019-3882
- EPSS 0.08%
- Published 24.04.2019 16:29:02
- Last modified 21.11.2024 04:42:47
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of th...
CVE-2019-3901
- EPSS 0.07%
- Published 22.04.2019 16:29:01
- Last modified 21.11.2024 04:42:49
A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target ...