CVE-2019-10160
- EPSS 2.14%
- Veröffentlicht 07.06.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:32
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by...
CVE-2019-12614
- EPSS 0.09%
- Veröffentlicht 03.06.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:23:11
An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dere...
CVE-2019-3846
- EPSS 0.38%
- Veröffentlicht 03.06.2019 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:42:41
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
CVE-2019-8457
- EPSS 27.14%
- Veröffentlicht 30.05.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:49:56
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
CVE-2019-12447
- EPSS 0.6%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:52
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
CVE-2019-12449
- EPSS 0.6%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:52
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges...
CVE-2019-12450
- EPSS 0.9%
- Veröffentlicht 29.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:52
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
CVE-2019-5436
- EPSS 29.54%
- Veröffentlicht 28.05.2019 19:29:06
- Zuletzt bearbeitet 21.11.2024 04:44:55
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
CVE-2019-5798
- EPSS 1.37%
- Veröffentlicht 23.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:30
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2019-5799
- EPSS 0.24%
- Veröffentlicht 23.05.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:31
Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.