CVE-2019-15718
- EPSS 0.11%
- Veröffentlicht 04.09.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:29:19
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivile...
CVE-2019-14811
- EPSS 1.73%
- Veröffentlicht 03.09.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:24
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disabl...
CVE-2019-14817
- EPSS 0.36%
- Veröffentlicht 03.09.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:27:25
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could dis...
CVE-2019-12402
- EPSS 0.38%
- Veröffentlicht 30.08.2019 09:15:17
- Zuletzt bearbeitet 21.11.2024 04:22:45
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names insi...
CVE-2019-11500
- EPSS 41.53%
- Veröffentlicht 29.08.2019 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:12
In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writes and remote code execution.
CVE-2019-15538
- EPSS 16.43%
- Veröffentlicht 25.08.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:57
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_...
CVE-2019-15531
- EPSS 1.11%
- Veröffentlicht 23.08.2019 17:15:14
- Zuletzt bearbeitet 21.11.2024 04:28:56
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
CVE-2019-10746
- EPSS 1.13%
- Veröffentlicht 23.08.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:19:50
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
CVE-2019-10086
- EPSS 0.32%
- Veröffentlicht 20.08.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-2126
- EPSS 9.31%
- Veröffentlicht 20.08.2019 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:40:16
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitat...