CVE-2019-2910
- EPSS 0.48%
- Veröffentlicht 16.10.2019 18:15:27
- Zuletzt bearbeitet 21.11.2024 04:41:47
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Difficult to exploit vulnerability allows unauthenticated attacker wi...
- EPSS 0.19%
- Veröffentlicht 16.10.2019 18:15:27
- Zuletzt bearbeitet 21.11.2024 04:41:47
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attac...
CVE-2019-2894
- EPSS 0.35%
- Veröffentlicht 16.10.2019 18:15:26
- Zuletzt bearbeitet 21.11.2024 04:41:45
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthen...
CVE-2019-17539
- EPSS 0.67%
- Veröffentlicht 14.10.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:28
In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.
CVE-2019-17542
- EPSS 0.82%
- Veröffentlicht 14.10.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:29
FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.
CVE-2019-17544
- EPSS 0.36%
- Veröffentlicht 14.10.2019 02:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:29
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
CVE-2019-2215
- EPSS 49.67%
- Veröffentlicht 11.10.2019 19:15:10
- Zuletzt bearbeitet 24.10.2025 14:11:31
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local appli...
CVE-2019-17455
- EPSS 7.08%
- Veröffentlicht 10.10.2019 18:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:21
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a craf...
CVE-2019-17450
- EPSS 1.09%
- Veröffentlicht 10.10.2019 17:15:17
- Zuletzt bearbeitet 21.11.2024 04:32:20
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
CVE-2019-17451
- EPSS 1.06%
- Veröffentlicht 10.10.2019 17:15:17
- Zuletzt bearbeitet 21.11.2024 04:32:20
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.