CVE-2019-1999
- EPSS 0.6%
- Veröffentlicht 28.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:51
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for ex...
CVE-2019-9208
- EPSS 4.24%
- Veröffentlicht 28.02.2019 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:12
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.
CVE-2019-9209
- EPSS 0.52%
- Veröffentlicht 28.02.2019 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:12
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
CVE-2019-9214
- EPSS 4.81%
- Veröffentlicht 28.02.2019 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:13
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.
CVE-2019-9215
- EPSS 0.9%
- Veröffentlicht 28.02.2019 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:13
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
CVE-2019-1559
- EPSS 4.96%
- Veröffentlicht 27.02.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:36:48
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid...
CVE-2019-9210
- EPSS 0.43%
- Veröffentlicht 27.02.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:12
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
CVE-2019-9200
- EPSS 5.3%
- Veröffentlicht 26.02.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:11
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmen...
CVE-2019-9020
- EPSS 2.39%
- Veröffentlicht 22.02.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:49
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is rel...
CVE-2019-9021
- EPSS 25.11%
- Veröffentlicht 22.02.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:50:49
An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory ...