CVE-2017-5332
- EPSS 0.23%
- Published 04.11.2019 21:15:11
- Last modified 21.11.2024 03:27:24
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
CVE-2017-5333
- EPSS 0.23%
- Published 04.11.2019 21:15:11
- Last modified 21.11.2024 03:27:24
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
- EPSS 1.06%
- Published 04.11.2019 16:15:11
- Last modified 21.11.2024 04:33:31
An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. ...
CVE-2019-6470
- EPSS 0.27%
- Published 01.11.2019 23:15:10
- Last modified 11.04.2025 14:55:14
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function...
CVE-2019-5010
- EPSS 3.67%
- Published 31.10.2019 21:15:13
- Last modified 21.11.2024 04:44:10
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can ini...
CVE-2019-18424
- EPSS 0.12%
- Published 31.10.2019 14:15:12
- Last modified 21.11.2024 04:33:14
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after...
CVE-2019-18425
- EPSS 4.87%
- Published 31.10.2019 14:15:12
- Last modified 21.11.2024 04:33:14
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest ope...
CVE-2019-18421
- EPSS 1.96%
- Published 31.10.2019 14:15:10
- Last modified 21.11.2024 04:33:13
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoi...
CVE-2019-17596
- EPSS 2.34%
- Published 24.10.2019 22:15:10
- Last modified 21.11.2024 04:32:36
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
CVE-2019-17498
- EPSS 1.25%
- Published 21.10.2019 22:15:10
- Last modified 21.11.2024 04:32:22
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be ...