- EPSS 0.1%
- Veröffentlicht 29.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:31
A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest, under specific conditions, can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory co...
CVE-2019-7150
- EPSS 0.13%
- Veröffentlicht 29.01.2019 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:40
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted inp...
CVE-2019-3462
- EPSS 6.99%
- Veröffentlicht 28.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:05
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
CVE-2018-10910
- EPSS 0.06%
- Veröffentlicht 28.01.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:16
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain Bluetooth devices without any form of authentication...
CVE-2019-6978
- EPSS 3.61%
- Veröffentlicht 28.01.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:21
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
CVE-2019-6977
- EPSS 87.77%
- Veröffentlicht 27.01.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:47:20
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This c...
CVE-2019-3819
- EPSS 0.01%
- Veröffentlicht 25.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:36
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up...
CVE-2019-6706
- EPSS 0.9%
- Veröffentlicht 23.01.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:59
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
CVE-2018-5740
- EPSS 69.02%
- Veröffentlicht 16.01.2019 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:17
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feat...
CVE-2017-3144
- EPSS 17.59%
- Veröffentlicht 16.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:55
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older ve...