CVE-2019-18805
- EPSS 0.57%
- Veröffentlicht 07.11.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:36
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen...
- EPSS 1.06%
- Veröffentlicht 04.11.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:31
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. ...
CVE-2019-17498
- EPSS 1.25%
- Veröffentlicht 21.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:22
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be ...
CVE-2019-2215
- EPSS 49.83%
- Veröffentlicht 11.10.2019 19:15:10
- Zuletzt bearbeitet 04.04.2025 15:40:44
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local appli...
CVE-2019-15166
- EPSS 1.02%
- Veröffentlicht 03.10.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:11
lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
CVE-2019-16995
- EPSS 2%
- Veröffentlicht 30.09.2019 13:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:30
In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d.
CVE-2019-5094
- EPSS 0.31%
- Veröffentlicht 24.09.2019 22:15:13
- Zuletzt bearbeitet 30.05.2025 19:15:24
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition ...
CVE-2019-14814
- EPSS 0.25%
- Veröffentlicht 20.09.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:24
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
CVE-2019-14816
- EPSS 0.23%
- Veröffentlicht 20.09.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:25
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
CVE-2019-14821
- EPSS 0.05%
- Veröffentlicht 19.09.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:25
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wher...