CVE-2019-5808
- EPSS 2.61%
- Published 27.06.2019 17:15:13
- Last modified 21.11.2024 04:45:32
Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- EPSS 5.24%
- Published 26.06.2019 16:15:09
- Last modified 21.11.2024 04:18:33
PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often su...
- EPSS 0.07%
- Published 25.06.2019 12:15:11
- Last modified 21.11.2024 04:23:38
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of pow...
CVE-2019-12957
- EPSS 0.3%
- Published 25.06.2019 00:15:09
- Last modified 21.11.2024 04:23:53
In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the index number is larger than the charset array bounds. It can, for example, be triggered by sending a crafted PDF document to the pdfto...
CVE-2018-20843
- EPSS 5.82%
- Published 24.06.2019 17:15:09
- Last modified 30.05.2025 20:15:20
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).
CVE-2019-11038
- EPSS 8.29%
- Published 19.06.2019 00:15:12
- Last modified 21.11.2024 04:20:25
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause t...
CVE-2019-12802
- EPSS 0.47%
- Published 13.06.2019 21:29:16
- Last modified 21.11.2024 04:23:36
In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r...
CVE-2019-10155
- EPSS 0.23%
- Published 12.06.2019 14:29:02
- Last modified 21.11.2024 04:18:32
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check v...
CVE-2019-0197
- EPSS 2.09%
- Published 11.06.2019 22:29:04
- Last modified 21.11.2024 04:16:27
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection cou...
CVE-2019-0220
- EPSS 17.93%
- Published 11.06.2019 21:29:00
- Last modified 21.11.2024 04:16:31
A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions...