CVE-2019-3811
- EPSS 0.12%
- Veröffentlicht 15.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:35
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem ac...
CVE-2019-6256
- EPSS 0.56%
- Veröffentlicht 14.01.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:19
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie H...
- EPSS 29.07%
- Veröffentlicht 13.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:18
A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::size_ready integer overflow allows an authenticated attacker to overwrite an arbitrary amount of byte...
CVE-2019-6245
- EPSS 0.61%
- Veröffentlicht 13.01.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:18
An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned to (x2 - x1). If dx >= dx_limit, which is (16384 << poly_subpixel_shift), this function will call its...
CVE-2018-16865
- EPSS 1.22%
- Veröffentlicht 11.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remo...
CVE-2018-16864
- EPSS 0.15%
- Veröffentlicht 11.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash s...
CVE-2018-16866
- EPSS 0.06%
- Veröffentlicht 11.01.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
CVE-2018-4180
- EPSS 0.12%
- Veröffentlicht 11.01.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:55
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
CVE-2018-4181
- EPSS 0.1%
- Veröffentlicht 11.01.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:55
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
CVE-2019-6133
- EPSS 0.03%
- Veröffentlicht 11.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:00
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendin...