CVE-2019-15142
- EPSS 0.18%
- Veröffentlicht 18.08.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:08
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
CVE-2019-15143
- EPSS 0.07%
- Veröffentlicht 18.08.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:09
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/...
CVE-2019-15144
- EPSS 0.06%
- Veröffentlicht 18.08.2019 19:15:09
- Zuletzt bearbeitet 21.11.2024 04:28:09
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h...
CVE-2019-15118
- EPSS 0.13%
- Veröffentlicht 16.08.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:28:05
check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15098
- EPSS 0.16%
- Veröffentlicht 16.08.2019 02:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:02
drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.
CVE-2019-15090
- EPSS 0.11%
- Veröffentlicht 16.08.2019 00:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:02
An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds read.
CVE-2019-9850
- EPSS 2.71%
- Veröffentlicht 15.08.2019 22:15:22
- Zuletzt bearbeitet 21.11.2024 04:52:26
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify tha...
CVE-2019-9851
- EPSS 85.95%
- Veröffentlicht 15.08.2019 22:15:22
- Zuletzt bearbeitet 21.11.2024 04:52:26
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calli...
CVE-2019-9852
- EPSS 0.11%
- Veröffentlicht 15.08.2019 22:15:22
- Zuletzt bearbeitet 21.11.2024 04:52:26
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Script...
CVE-2019-12854
- EPSS 44.49%
- Veröffentlicht 15.08.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:23:43
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clien...