CVE-2019-3819
- EPSS 0.03%
- Veröffentlicht 25.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:36
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up...
CVE-2018-20743
- EPSS 7.52%
- Veröffentlicht 25.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:04
murmur in Mumble through 1.2.19 before 2018-08-31 mishandles multiple concurrent requests that are persisted in the database, which allows remote attackers to cause a denial of service (daemon hang or crash) via a message flood.
CVE-2019-6956
- EPSS 0.36%
- Veröffentlicht 25.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:17
An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.
CVE-2017-18359
- EPSS 2.07%
- Veröffentlicht 25.01.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:55
PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server termination for "SELECT ST_AsX3D('LINESTRING EMPTY');" because empty ge...
CVE-2019-6486
- EPSS 2.4%
- Veröffentlicht 24.01.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:32
Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.
CVE-2017-6922
- EPSS 2.72%
- Veröffentlicht 22.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rathe...
CVE-2019-6339
- EPSS 80.78%
- Veröffentlicht 22.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:26
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulnerability exists in PHP's built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code...
- EPSS 1.09%
- Veröffentlicht 22.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:26
In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-party PEAR Archive_Tar library. This library has released a security update which impacts some Drupal configurations. Refer to CVE-20...
CVE-2018-5740
- EPSS 57.94%
- Veröffentlicht 16.01.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:17
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feat...
CVE-2017-3135
- EPSS 35.33%
- Veröffentlicht 16.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:54
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3...