CVE-2019-19054
- EPSS 0.04%
- Veröffentlicht 18.11.2019 06:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:05
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42...
CVE-2019-18978
- EPSS 1.02%
- Veröffentlicht 14.11.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:55
An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2018-12207
- EPSS 0.26%
- Veröffentlicht 14.11.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 03:44:45
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
CVE-2019-11135
- EPSS 0.32%
- Veröffentlicht 14.11.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:20:35
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2019-0154
- EPSS 0.11%
- Veröffentlicht 14.11.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:16:21
Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 ...
CVE-2019-0155
- EPSS 0.09%
- Veröffentlicht 14.11.2019 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:16:21
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G390...
CVE-2019-2214
- EPSS 0.05%
- Veröffentlicht 13.11.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:40:26
In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...
CVE-2019-2201
- EPSS 1.08%
- Veröffentlicht 13.11.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:40:25
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. U...
CVE-2019-18849
- EPSS 1.02%
- Veröffentlicht 11.11.2019 04:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:42
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
CVE-2013-1429
- EPSS 1%
- Veröffentlicht 07.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:49:33
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.