CVE-2019-3839
- EPSS 0.17%
- Published 16.05.2019 19:29:05
- Last modified 21.11.2024 04:42:40
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside o...
CVE-2019-12098
- EPSS 4.74%
- Published 15.05.2019 23:29:00
- Last modified 21.11.2024 04:22:11
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
CVE-2019-12111
- EPSS 1.03%
- Published 15.05.2019 23:29:00
- Last modified 21.11.2024 04:22:13
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
CVE-2019-11833
- EPSS 0.03%
- Published 15.05.2019 13:29:00
- Last modified 21.11.2024 04:21:51
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
CVE-2019-11884
- EPSS 0.05%
- Published 10.05.2019 22:29:00
- Last modified 21.11.2024 04:21:57
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a...
CVE-2019-11840
- EPSS 2.76%
- Published 09.05.2019 16:29:00
- Last modified 21.11.2024 04:21:52
An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/sals...
CVE-2019-11831
- EPSS 8.09%
- Published 09.05.2019 04:29:01
- Last modified 21.11.2024 04:21:50
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/b...
CVE-2019-11815
- EPSS 1.19%
- Published 08.05.2019 14:29:00
- Last modified 21.11.2024 04:21:49
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
CVE-2018-20836
- EPSS 3.96%
- Published 07.05.2019 14:29:00
- Last modified 21.11.2024 04:02:16
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
CVE-2019-11810
- EPSS 1.88%
- Published 07.05.2019 14:29:00
- Last modified 21.11.2024 04:21:48
An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a ...