CVE-2019-12216
- EPSS 1.13%
- Veröffentlicht 20.05.2019 17:29:17
- Zuletzt bearbeitet 21.11.2024 04:22:26
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX_RW at IMG_pcx.c.
CVE-2019-12221
- EPSS 2.11%
- Veröffentlicht 20.05.2019 17:29:17
- Zuletzt bearbeitet 21.11.2024 04:22:27
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
CVE-2019-12213
- EPSS 0.34%
- Veröffentlicht 20.05.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:22:26
When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion.
CVE-2019-3839
- EPSS 0.17%
- Veröffentlicht 16.05.2019 19:29:05
- Zuletzt bearbeitet 21.11.2024 04:42:40
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside o...
CVE-2019-12098
- EPSS 4.8%
- Veröffentlicht 15.05.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:22:11
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
CVE-2019-8936
- EPSS 24.49%
- Veröffentlicht 15.05.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:50:41
NTP through 4.2.8p12 has a NULL Pointer Dereference.
CVE-2019-11833
- EPSS 0.03%
- Veröffentlicht 15.05.2019 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:51
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
- EPSS 0.84%
- Veröffentlicht 14.05.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:20:53
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/in...
CVE-2019-12083
- EPSS 0.78%
- Veröffentlicht 13.05.2019 20:29:02
- Zuletzt bearbeitet 21.11.2024 04:22:10
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be s...
CVE-2019-11884
- EPSS 0.05%
- Veröffentlicht 10.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:57
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a...