CVE-2019-12083
- EPSS 0.85%
- Veröffentlicht 13.05.2019 20:29:02
- Zuletzt bearbeitet 21.11.2024 04:22:10
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be s...
CVE-2019-11884
- EPSS 0.05%
- Veröffentlicht 10.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:57
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a...
CVE-2019-11494
- EPSS 0.86%
- Veröffentlicht 08.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:11
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
- EPSS 3.71%
- Veröffentlicht 08.05.2019 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:44:12
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deploye...
CVE-2019-11499
- EPSS 0.75%
- Veröffentlicht 08.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:12
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.
CVE-2019-11815
- EPSS 1.19%
- Veröffentlicht 08.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:49
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
CVE-2019-7443
- EPSS 1.66%
- Veröffentlicht 07.05.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:48:14
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. I...
CVE-2018-19456
- EPSS 0.65%
- Veröffentlicht 07.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:57
The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql.
CVE-2018-20836
- EPSS 1.88%
- Veröffentlicht 07.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:16
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
- EPSS 0.07%
- Veröffentlicht 07.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:48
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/char/ipmi/ipmi_si_mem_io.c, and ...