CVE-2019-11035
- EPSS 3.59%
- Published 18.04.2019 17:29:00
- Last modified 21.11.2024 04:20:24
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
CVE-2016-10746
- EPSS 0.56%
- Published 18.04.2019 16:29:00
- Last modified 21.11.2024 02:44:39
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
CVE-2019-9498
- EPSS 1.06%
- Published 17.04.2019 14:29:04
- Last modified 21.11.2024 04:51:44
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar...
CVE-2019-9499
- EPSS 1.06%
- Published 17.04.2019 14:29:04
- Last modified 21.11.2024 04:51:44
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication,...
CVE-2019-3883
- EPSS 0.4%
- Published 17.04.2019 14:29:03
- Last modified 21.11.2024 04:42:47
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are ...
CVE-2019-9495
- EPSS 6.03%
- Published 17.04.2019 14:29:03
- Last modified 21.11.2024 04:51:43
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execu...
CVE-2019-11221
- EPSS 0.19%
- Published 15.04.2019 12:31:36
- Last modified 21.11.2024 04:20:45
GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.
CVE-2019-11222
- EPSS 0.46%
- Published 15.04.2019 12:31:36
- Last modified 21.11.2024 04:20:45
gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.
CVE-2019-3459
- EPSS 0.48%
- Published 11.04.2019 16:29:02
- Last modified 21.11.2024 04:42:05
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
CVE-2019-3460
- EPSS 0.48%
- Published 11.04.2019 16:29:02
- Last modified 21.11.2024 04:42:05
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.