CVE-2019-19925
- EPSS 9.23%
- Published 24.12.2019 17:15:10
- Last modified 21.11.2024 04:35:40
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
CVE-2019-19923
- EPSS 10.52%
- Published 24.12.2019 16:15:11
- Last modified 21.11.2024 04:35:40
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
CVE-2019-19948
- EPSS 0.53%
- Published 24.12.2019 01:15:11
- Last modified 21.11.2024 04:35:43
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
CVE-2019-19949
- EPSS 0.32%
- Published 24.12.2019 01:15:11
- Last modified 21.11.2024 04:35:43
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
CVE-2019-19950
- EPSS 1.2%
- Published 24.12.2019 01:15:11
- Last modified 21.11.2024 04:35:43
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
CVE-2019-19951
- EPSS 1.44%
- Published 24.12.2019 01:15:11
- Last modified 21.11.2024 04:35:43
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
CVE-2019-19953
- EPSS 1.31%
- Published 24.12.2019 01:15:11
- Last modified 21.11.2024 04:35:44
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
- EPSS 0.87%
- Published 23.12.2019 18:15:10
- Last modified 21.11.2024 04:22:48
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perf...
CVE-2019-17563
- EPSS 3.26%
- Published 23.12.2019 17:15:11
- Last modified 21.11.2024 04:32:32
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be p...
CVE-2019-18388
- EPSS 0.02%
- Published 23.12.2019 16:15:11
- Last modified 21.11.2024 04:33:11
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.