CVE-2019-1010228
- EPSS 0.28%
- Published 22.07.2019 17:15:38
- Last modified 21.11.2024 04:18:04
OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Denial of Service. The component is: DcmRLEDecoder::decompress() (file dcrledec.h, line 122). The attack vector is: Many scenarios of...
CVE-2019-9959
- EPSS 1.49%
- Published 22.07.2019 15:15:10
- Last modified 21.11.2024 04:52:40
The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attac...
CVE-2019-12815
- EPSS 83.99%
- Published 19.07.2019 23:15:11
- Last modified 21.11.2024 04:23:38
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVE-2019-1010238
- EPSS 4.92%
- Published 19.07.2019 17:15:11
- Last modified 21.11.2024 04:18:04
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condit...
CVE-2019-1010142
- EPSS 1.93%
- Published 19.07.2019 16:15:12
- Last modified 21.11.2024 04:17:59
scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector is: over the network or in a pcap. both work.
CVE-2019-1010065
- EPSS 1.18%
- Published 18.07.2019 17:15:11
- Last modified 21.11.2024 04:17:57
The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hf...
CVE-2019-13619
- EPSS 9.82%
- Published 17.07.2019 20:15:11
- Last modified 21.11.2024 04:25:22
In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.
CVE-2019-13626
- EPSS 0.69%
- Published 17.07.2019 16:15:12
- Last modified 21.11.2024 04:25:23
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
CVE-2019-13272
- EPSS 81.24%
- Published 17.07.2019 13:15:10
- Last modified 03.04.2025 20:28:35
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with...
CVE-2019-9848
- EPSS 86.56%
- Published 17.07.2019 12:15:10
- Last modified 21.11.2024 04:52:25
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, w...