CVE-2019-19947
- EPSS 0.11%
- Published 24.12.2019 00:15:10
- Last modified 21.11.2024 04:35:43
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
CVE-2019-3467
- EPSS 0.09%
- Published 23.12.2019 19:15:11
- Last modified 21.11.2024 04:42:06
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
CVE-2019-5108
- EPSS 0.68%
- Published 23.12.2019 19:15:11
- Last modified 21.11.2024 04:44:22
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has c...
- EPSS 0.87%
- Published 23.12.2019 18:15:10
- Last modified 21.11.2024 04:22:48
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perf...
CVE-2019-17563
- EPSS 3.26%
- Published 23.12.2019 17:15:11
- Last modified 21.11.2024 04:32:32
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be p...
CVE-2019-18388
- EPSS 0.02%
- Published 23.12.2019 16:15:11
- Last modified 21.11.2024 04:33:11
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands.
CVE-2019-18389
- EPSS 0.07%
- Published 23.12.2019 16:15:11
- Last modified 21.11.2024 04:33:11
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESO...
CVE-2019-18390
- EPSS 0.03%
- Published 23.12.2019 16:15:11
- Last modified 21.11.2024 04:33:11
An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
CVE-2019-18391
- EPSS 0.03%
- Published 23.12.2019 16:15:11
- Last modified 21.11.2024 04:33:11
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
CVE-2019-11045
- EPSS 35.84%
- Published 23.12.2019 03:15:11
- Last modified 21.11.2024 04:20:26
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications check...