CVE-2019-19949
- EPSS 0.34%
- Veröffentlicht 24.12.2019 01:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:43
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
CVE-2019-19947
- EPSS 0.11%
- Veröffentlicht 24.12.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:43
In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.
CVE-2019-3467
- EPSS 0.09%
- Veröffentlicht 23.12.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:42:06
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.
CVE-2019-5108
- EPSS 0.68%
- Veröffentlicht 23.12.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:22
An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has c...
- EPSS 0.47%
- Veröffentlicht 23.12.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:48
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perf...
CVE-2019-17563
- EPSS 2.43%
- Veröffentlicht 23.12.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:32
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be p...
CVE-2019-11045
- EPSS 40.95%
- Veröffentlicht 23.12.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:26
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications check...
CVE-2019-11046
- EPSS 8.25%
- Veröffentlicht 23.12.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:26
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters that are ide...
CVE-2019-11047
- EPSS 3.17%
- Veröffentlicht 23.12.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:26
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocate...
CVE-2019-11050
- EPSS 3.12%
- Veröffentlicht 23.12.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:20:27
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocate...