CVE-2019-14899
- EPSS 0.84%
- Veröffentlicht 11.12.2019 15:15:14
- Zuletzt bearbeitet 21.11.2024 04:27:38
A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiti...
CVE-2019-19449
- EPSS 2.01%
- Veröffentlicht 08.12.2019 02:15:09
- Zuletzt bearbeitet 21.11.2024 04:34:45
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get...
CVE-2019-19378
- EPSS 2.35%
- Veröffentlicht 29.11.2019 17:15:11
- Zuletzt bearbeitet 28.05.2026 19:16:34
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in index_rbio_pages in fs/btrfs/raid56.c.
CVE-2019-19377
- EPSS 3.4%
- Veröffentlicht 29.11.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:34:40
In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can lead to a use-after-free in btrfs_queue_work in fs/btrfs/async-thread.c.
CVE-2019-19036
- EPSS 1.84%
- Veröffentlicht 21.11.2019 02:15:23
- Zuletzt bearbeitet 21.11.2024 04:34:02
btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_dereference(root->node) can be zero.
CVE-2019-19039
- EPSS 0.7%
- Veröffentlicht 21.11.2019 02:15:23
- Zuletzt bearbeitet 21.11.2024 04:34:02
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: ...
CVE-2019-0146
- EPSS 0.29%
- Veröffentlicht 14.11.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:16:19
Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.
CVE-2019-16230
- EPSS 0.38%
- Veröffentlicht 11.09.2019 16:15:11
- Zuletzt bearbeitet 28.05.2026 19:16:31
drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer states that the work queue allocation is happening duri...
CVE-2018-7191
- EPSS 0.65%
- Veröffentlicht 17.05.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:45
In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev nam...
CVE-2019-3900
- EPSS 4.35%
- Veröffentlicht 25.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:49
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest ...