CVE-2019-9325
- EPSS 4.98%
- Published 27.09.2019 19:15:21
- Last modified 21.11.2024 04:51:25
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: A...
CVE-2019-9278
- EPSS 7.45%
- Published 27.09.2019 19:15:19
- Last modified 21.11.2024 04:51:20
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitatio...
CVE-2019-9232
- EPSS 2.65%
- Published 27.09.2019 19:15:17
- Last modified 21.11.2024 04:51:15
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...
CVE-2019-11735
- EPSS 0.46%
- Published 27.09.2019 18:15:11
- Last modified 21.11.2024 04:21:41
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run...
CVE-2019-11738
- EPSS 0.59%
- Published 27.09.2019 18:15:11
- Last modified 21.11.2024 04:21:41
If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP ...
CVE-2019-11740
- EPSS 1.5%
- Published 27.09.2019 18:15:11
- Last modified 21.11.2024 04:21:41
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be e...
CVE-2019-10092
- EPSS 82.38%
- Published 26.09.2019 16:15:10
- Last modified 21.11.2024 04:18:23
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only ...
CVE-2019-16884
- EPSS 0.28%
- Published 25.09.2019 18:15:13
- Last modified 21.11.2024 04:31:16
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc direct...
CVE-2019-13627
- EPSS 0.03%
- Published 25.09.2019 15:15:11
- Last modified 21.11.2024 04:25:23
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
CVE-2019-12068
- EPSS 0.1%
- Published 24.09.2019 20:15:11
- Last modified 21.11.2024 04:22:10
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read ne...