CVE-2019-6501
- EPSS 0.12%
- Veröffentlicht 21.03.2019 16:01:08
- Zuletzt bearbeitet 21.11.2024 04:46:34
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
CVE-2019-6116
- EPSS 67.78%
- Veröffentlicht 21.03.2019 16:01:07
- Zuletzt bearbeitet 21.11.2024 04:45:58
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
CVE-2019-5885
- EPSS 0.79%
- Veröffentlicht 21.03.2019 16:01:05
- Zuletzt bearbeitet 21.11.2024 04:45:42
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
CVE-2019-3859
- EPSS 0.88%
- Veröffentlicht 21.03.2019 16:01:04
- Zuletzt bearbeitet 18.12.2025 12:15:53
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the clien...
CVE-2019-3862
- EPSS 5.63%
- Veröffentlicht 21.03.2019 16:01:04
- Zuletzt bearbeitet 21.11.2024 04:42:44
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Servic...
CVE-2018-19872
- EPSS 0.27%
- Veröffentlicht 21.03.2019 16:00:32
- Zuletzt bearbeitet 21.11.2024 03:58:43
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
CVE-2018-18849
- EPSS 0.05%
- Veröffentlicht 21.03.2019 16:00:29
- Zuletzt bearbeitet 21.11.2024 03:56:44
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
CVE-2018-18898
- EPSS 1.44%
- Veröffentlicht 21.03.2019 16:00:29
- Zuletzt bearbeitet 21.11.2024 03:56:50
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
CVE-2018-12022
- EPSS 3.04%
- Veröffentlicht 21.03.2019 16:00:12
- Zuletzt bearbeitet 21.11.2024 03:44:25
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in ...
CVE-2018-12023
- EPSS 4.81%
- Veröffentlicht 21.03.2019 16:00:12
- Zuletzt bearbeitet 21.11.2024 03:44:26
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provid...