CVE-2019-16781
- EPSS 3.49%
- Veröffentlicht 26.12.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:10
In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading t...
CVE-2019-16789
- EPSS 0.88%
- Veröffentlicht 26.12.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:11
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Spec...
CVE-2019-19965
- EPSS 0.05%
- Veröffentlicht 25.12.2019 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:45
In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-19966
- EPSS 0.14%
- Veröffentlicht 25.12.2019 04:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:45
In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.
CVE-2019-19925
- EPSS 7.01%
- Veröffentlicht 24.12.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:40
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
CVE-2019-19923
- EPSS 6.2%
- Veröffentlicht 24.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:40
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).
CVE-2019-19956
- EPSS 0.21%
- Veröffentlicht 24.12.2019 16:15:11
- Zuletzt bearbeitet 03.12.2025 19:15:50
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
CVE-2019-19948
- EPSS 0.39%
- Veröffentlicht 24.12.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:43
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
CVE-2019-19949
- EPSS 0.34%
- Veröffentlicht 24.12.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:43
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
CVE-2019-19950
- EPSS 1.2%
- Veröffentlicht 24.12.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:43
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.