CVE-2017-18635
- EPSS 8.31%
- Veröffentlicht 25.09.2019 23:15:09
- Zuletzt bearbeitet 21.11.2024 03:20:32
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
CVE-2019-16884
- EPSS 0.57%
- Veröffentlicht 25.09.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:16
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc direct...
CVE-2019-13627
- EPSS 0.04%
- Veröffentlicht 25.09.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:23
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions fixed: 1.8.5-2 and 1.6.3-2+deb8u7.
CVE-2019-5094
- EPSS 0.31%
- Veröffentlicht 24.09.2019 22:15:13
- Zuletzt bearbeitet 30.05.2025 19:15:24
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition ...
CVE-2019-12068
- EPSS 0.09%
- Veröffentlicht 24.09.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:22:10
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read ne...
CVE-2019-16746
- EPSS 2.6%
- Veröffentlicht 24.09.2019 06:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:06
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
CVE-2019-16729
- EPSS 0.06%
- Veröffentlicht 24.09.2019 05:15:11
- Zuletzt bearbeitet 21.11.2024 04:31:04
pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.
CVE-2019-16708
- EPSS 0.19%
- Veröffentlicht 23.09.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:01
ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
CVE-2019-16709
- EPSS 0.19%
- Veröffentlicht 23.09.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:01
ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
CVE-2019-16710
- EPSS 0.19%
- Veröffentlicht 23.09.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:01
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.