CVE-2019-18425
- EPSS 4.87%
- Veröffentlicht 31.10.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:14
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest ope...
CVE-2019-18423
- EPSS 5.45%
- Veröffentlicht 31.10.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:33:14
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() and p2m_get_entry() to sanity c...
CVE-2019-18420
- EPSS 4.25%
- Veröffentlicht 31.10.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:13
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret it...
CVE-2019-18421
- EPSS 1.96%
- Veröffentlicht 31.10.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:13
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoi...
CVE-2019-18422
- EPSS 3.77%
- Veröffentlicht 31.10.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:14
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an excep...
CVE-2018-21029
- EPSS 1.56%
- Veröffentlicht 30.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:02:43
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the dev...
CVE-2019-11043
- EPSS 94.11%
- Veröffentlicht 28.10.2019 15:15:13
- Zuletzt bearbeitet 14.02.2025 16:43:36
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the p...
CVE-2019-17596
- EPSS 2.34%
- Veröffentlicht 24.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:36
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
CVE-2019-15587
- EPSS 2.21%
- Veröffentlicht 22.10.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:04
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVE-2019-17498
- EPSS 1.25%
- Veröffentlicht 21.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:22
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be ...