CVE-2019-18421
- EPSS 1.96%
- Veröffentlicht 31.10.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:13
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoi...
CVE-2019-18422
- EPSS 3.77%
- Veröffentlicht 31.10.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 04:33:14
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an excep...
CVE-2018-21029
- EPSS 1.56%
- Veröffentlicht 30.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:02:43
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the dev...
CVE-2019-11043
- EPSS 94.11%
- Veröffentlicht 28.10.2019 15:15:13
- Zuletzt bearbeitet 03.11.2025 19:23:46
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the p...
CVE-2019-17596
- EPSS 2.34%
- Veröffentlicht 24.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:36
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
CVE-2019-15587
- EPSS 3.03%
- Veröffentlicht 22.10.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 04:29:04
In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVE-2019-17498
- EPSS 2.03%
- Veröffentlicht 21.10.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:22
In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be ...
CVE-2019-18218
- EPSS 0.23%
- Veröffentlicht 21.10.2019 05:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:51
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
- EPSS 86.13%
- Veröffentlicht 17.10.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:26:22
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !r...
CVE-2019-3004
- EPSS 0.31%
- Veröffentlicht 16.10.2019 18:15:34
- Zuletzt bearbeitet 21.11.2024 04:41:58
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protoco...