CVE-2019-2422
- EPSS 0.28%
- Veröffentlicht 16.01.2019 19:30:31
- Zuletzt bearbeitet 21.11.2024 04:40:50
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker...
CVE-2018-20721
- EPSS 0.53%
- Veröffentlicht 16.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:01
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.
CVE-2018-14662
- EPSS 0.1%
- Veröffentlicht 15.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
CVE-2018-16846
- EPSS 4.77%
- Veröffentlicht 15.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:26
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
CVE-2019-3811
- EPSS 0.15%
- Veröffentlicht 15.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:35
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem ac...
CVE-2019-6256
- EPSS 0.58%
- Veröffentlicht 14.01.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:19
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie H...
- EPSS 34.64%
- Veröffentlicht 13.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:18
A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of byte...
CVE-2019-6245
- EPSS 0.32%
- Veröffentlicht 13.01.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:18
An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call its...
CVE-2018-16865
- EPSS 2.03%
- Veröffentlicht 11.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remo...
CVE-2018-16864
- EPSS 0.14%
- Veröffentlicht 11.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash s...