CVE-2019-0211
- EPSS 85.73%
- Published 08.04.2019 22:29:00
- Last modified 04.04.2025 15:34:11
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with...
CVE-2019-0217
- EPSS 34.78%
- Published 08.04.2019 21:29:00
- Last modified 21.11.2024 04:16:30
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictio...
CVE-2019-0215
- EPSS 8.97%
- Published 08.04.2019 20:29:10
- Last modified 21.11.2024 04:16:30
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
CVE-2019-10740
- EPSS 0.08%
- Published 07.04.2019 15:29:00
- Last modified 21.11.2024 04:19:49
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This ...
CVE-2019-10906
- EPSS 2.62%
- Published 07.04.2019 00:29:00
- Last modified 21.11.2024 04:20:06
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVE-2019-3886
- EPSS 0.53%
- Published 04.04.2019 16:29:03
- Last modified 21.11.2024 04:42:47
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causi...
CVE-2019-3836
- EPSS 0.37%
- Published 01.04.2019 15:29:01
- Last modified 21.11.2024 04:42:39
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
CVE-2018-12545
- EPSS 6.28%
- Published 27.03.2019 20:29:03
- Last modified 21.11.2024 03:45:24
In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to th...
CVE-2019-0160
- EPSS 0.33%
- Published 27.03.2019 20:29:03
- Last modified 21.11.2024 04:16:22
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
CVE-2019-3829
- EPSS 2.12%
- Published 27.03.2019 18:29:00
- Last modified 21.11.2024 04:42:37
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is...