CVE-2019-19553
- EPSS 0.66%
- Published 05.12.2019 01:15:14
- Last modified 21.11.2024 04:34:57
In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInfo dissection.
CVE-2018-12207
- EPSS 0.26%
- Published 14.11.2019 20:15:11
- Last modified 21.11.2024 03:44:45
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
CVE-2019-10219
- EPSS 1.67%
- Published 08.11.2019 15:15:11
- Last modified 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-3008
- EPSS 0.29%
- Published 16.10.2019 18:15:34
- Last modified 21.11.2024 04:41:58
Vulnerability in the Oracle Solaris product of Oracle Systems (component: LDAP Library). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle So...
CVE-2019-3010
- EPSS 33.46%
- Published 16.10.2019 18:15:34
- Last modified 07.02.2025 14:49:24
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solar...
CVE-2019-2961
- EPSS 0.14%
- Published 16.10.2019 18:15:31
- Last modified 21.11.2024 04:41:52
Vulnerability in the Oracle Solaris product of Oracle Systems (component: SMF services & legacy daemons). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure...
CVE-2019-2765
- EPSS 0.11%
- Published 16.10.2019 18:15:26
- Last modified 21.11.2024 04:41:31
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle...
CVE-2019-16168
- EPSS 0.84%
- Published 09.09.2019 17:15:13
- Last modified 21.11.2024 04:30:11
In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
CVE-2019-16056
- EPSS 0.58%
- Published 06.09.2019 18:15:15
- Last modified 21.11.2024 04:29:57
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and imple...
CVE-2019-13057
- EPSS 1.14%
- Published 26.07.2019 13:15:12
- Last modified 21.11.2024 04:24:07
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not pro...