CVE-2019-13619
- EPSS 9.82%
- Veröffentlicht 17.07.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:25:22
In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.
CVE-2019-13626
- EPSS 0.9%
- Veröffentlicht 17.07.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:23
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
CVE-2019-13272
- EPSS 81.25%
- Veröffentlicht 17.07.2019 13:15:10
- Zuletzt bearbeitet 06.11.2025 16:51:07
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with...
CVE-2019-9848
- EPSS 86.56%
- Veröffentlicht 17.07.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:25
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, w...
CVE-2019-9849
- EPSS 3.56%
- Veröffentlicht 17.07.2019 12:15:10
- Zuletzt bearbeitet 21.11.2024 04:52:26
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include rem...
CVE-2019-13115
- EPSS 42.82%
- Veröffentlicht 16.07.2019 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:24:13
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH serve...
CVE-2019-10190
- EPSS 0.26%
- Veröffentlicht 16.07.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:37
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-existence answer. NXDOMAIN answer would get passed through to the client ev...
CVE-2019-10191
- EPSS 0.27%
- Veröffentlicht 16.07.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:37
A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS pr...
CVE-2019-13616
- EPSS 6.52%
- Veröffentlicht 16.07.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:25:22
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
CVE-2019-1010057
- EPSS 0.63%
- Veröffentlicht 16.07.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:17:56
nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdum...