CVE-2019-9325
- EPSS 4.98%
- Veröffentlicht 27.09.2019 19:15:21
- Zuletzt bearbeitet 21.11.2024 04:51:25
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: A...
CVE-2019-9278
- EPSS 7.45%
- Veröffentlicht 27.09.2019 19:15:19
- Zuletzt bearbeitet 21.11.2024 04:51:20
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitatio...
CVE-2019-9232
- EPSS 2.65%
- Veröffentlicht 27.09.2019 19:15:17
- Zuletzt bearbeitet 21.11.2024 04:51:15
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersion...
CVE-2019-11735
- EPSS 0.46%
- Veröffentlicht 27.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:41
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run...
CVE-2019-11738
- EPSS 0.59%
- Veröffentlicht 27.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:41
If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP ...
CVE-2019-11740
- EPSS 1.5%
- Veröffentlicht 27.09.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:41
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be e...
CVE-2019-10092
- EPSS 82.38%
- Veröffentlicht 26.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:18:23
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only ...
CVE-2019-16884
- EPSS 0.28%
- Veröffentlicht 25.09.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:16
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc direct...
CVE-2019-13627
- EPSS 0.03%
- Veröffentlicht 25.09.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:23
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
CVE-2019-12068
- EPSS 0.1%
- Veröffentlicht 24.09.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:10
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read ne...