CVE-2019-11840
- EPSS 2.76%
- Veröffentlicht 09.05.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:52
An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/sals...
CVE-2019-11831
- EPSS 10.66%
- Veröffentlicht 09.05.2019 04:29:01
- Zuletzt bearbeitet 21.11.2024 04:21:50
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/b...
CVE-2019-11815
- EPSS 1.1%
- Veröffentlicht 08.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:49
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
CVE-2018-20836
- EPSS 3.96%
- Veröffentlicht 07.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:16
An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.
CVE-2019-11810
- EPSS 1.88%
- Veröffentlicht 07.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:48
An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a Denial of Service, related to a ...
CVE-2019-11766
- EPSS 0.78%
- Veröffentlicht 05.05.2019 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:45
dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
CVE-2019-11036
- EPSS 1.72%
- Veröffentlicht 03.05.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:24
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
- EPSS 0.49%
- Veröffentlicht 30.04.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:29
gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
CVE-2019-10131
- EPSS 0.13%
- Veröffentlicht 30.04.2019 19:29:03
- Zuletzt bearbeitet 21.11.2024 04:18:28
An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.
CVE-2019-5429
- EPSS 0.3%
- Veröffentlicht 29.04.2019 15:29:02
- Zuletzt bearbeitet 21.11.2024 04:44:55
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.