CVE-2019-11036
- EPSS 1.45%
- Published 03.05.2019 20:29:00
- Last modified 21.11.2024 04:20:24
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
CVE-2019-5429
- EPSS 0.66%
- Published 29.04.2019 15:29:02
- Last modified 21.11.2024 04:44:55
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
CVE-2019-3843
- EPSS 0.13%
- Published 26.04.2019 21:29:00
- Last modified 21.11.2024 04:42:41
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access res...
CVE-2019-3900
- EPSS 0.09%
- Published 25.04.2019 15:29:00
- Last modified 21.11.2024 04:42:49
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest ...
CVE-2019-3882
- EPSS 0.08%
- Published 24.04.2019 16:29:02
- Last modified 21.11.2024 04:42:47
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of th...
CVE-2019-11498
- EPSS 1.97%
- Published 24.04.2019 05:29:00
- Last modified 21.11.2024 04:21:12
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file ...
CVE-2019-2607
- EPSS 0.59%
- Published 23.04.2019 19:32:51
- Last modified 21.11.2024 04:41:12
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multipl...
CVE-2019-2614
- EPSS 0.16%
- Published 23.04.2019 19:32:51
- Last modified 21.11.2024 04:41:13
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileg...
CVE-2019-2617
- EPSS 0.23%
- Published 23.04.2019 19:32:51
- Last modified 21.11.2024 04:41:13
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via mul...
CVE-2019-2620
- EPSS 0.59%
- Published 23.04.2019 19:32:51
- Last modified 21.11.2024 04:41:13
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access ...