CVE-2019-9003
- EPSS 7.13%
- Veröffentlicht 22.02.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:47
In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.
CVE-2018-20783
- EPSS 6.65%
- Veröffentlicht 21.02.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:09
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. ...
CVE-2019-8980
- EPSS 2.2%
- Veröffentlicht 21.02.2019 05:29:01
- Zuletzt bearbeitet 21.11.2024 04:50:44
A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVE-2019-7164
- EPSS 1.98%
- Veröffentlicht 20.02.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:41
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
CVE-2019-3812
- EPSS 0.08%
- Veröffentlicht 19.02.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:35
QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memo...
CVE-2019-8912
- EPSS 0.36%
- Veröffentlicht 18.02.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:39
In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
CVE-2019-8906
- EPSS 0.08%
- Veröffentlicht 18.02.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:50:38
do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.
CVE-2019-8907
- EPSS 0.9%
- Veröffentlicht 18.02.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:50:38
do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.
CVE-2019-8905
- EPSS 0.1%
- Veröffentlicht 18.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:38
do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360.
CVE-2019-8341
- EPSS 22.01%
- Veröffentlicht 15.02.2019 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:49:43
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTI...