CVE-2019-17533
- EPSS 0.55%
- Veröffentlicht 13.10.2019 02:15:12
- Zuletzt bearbeitet 21.11.2024 04:32:28
Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed.
CVE-2019-17531
- EPSS 1.13%
- Veröffentlicht 12.10.2019 21:15:08
- Zuletzt bearbeitet 21.11.2024 04:32:27
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-ext...
CVE-2019-2215
- EPSS 51.02%
- Veröffentlicht 11.10.2019 19:15:10
- Zuletzt bearbeitet 24.10.2025 14:11:31
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local appli...
CVE-2019-17455
- EPSS 7.08%
- Veröffentlicht 10.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:21
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a craf...
CVE-2019-17402
- EPSS 0.22%
- Veröffentlicht 09.10.2019 19:15:14
- Zuletzt bearbeitet 21.11.2024 04:32:16
Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset an...
CVE-2019-17362
- EPSS 0.51%
- Veröffentlicht 09.10.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:11
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and cr...
CVE-2019-14846
- EPSS 0.14%
- Veröffentlicht 08.10.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:29
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBU...
CVE-2019-17349
- EPSS 0.14%
- Veröffentlicht 08.10.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:08
An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.
CVE-2019-17340
- EPSS 0.08%
- Veröffentlicht 08.10.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:07
An issue was discovered in Xen through 4.11.x allowing x86 guest OS users to cause a denial of service or gain privileges because grant-table transfer requests are mishandled.
CVE-2019-17341
- EPSS 0.11%
- Veröffentlicht 08.10.2019 01:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:07
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.