Show filters
112 Total Results
Displaying 11-20 of 112
Sort by:
Attacker Value
Unknown
CVE-2019-11328
Disclosure Date: May 14, 2019 (last updated November 08, 2023)
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.
0
Attacker Value
Unknown
CVE-2019-11884
Disclosure Date: May 10, 2019 (last updated November 08, 2023)
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
0
Attacker Value
Unknown
CVE-2019-11831
Disclosure Date: May 09, 2019 (last updated November 08, 2023)
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
0
Attacker Value
Unknown
CVE-2019-7443
Disclosure Date: May 07, 2019 (last updated November 08, 2023)
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
0
Attacker Value
Unknown
Heap over-read in PHP EXIF extension
Disclosure Date: May 03, 2019 (last updated November 08, 2023)
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
0
Attacker Value
Unknown
CVE-2019-5429
Disclosure Date: April 29, 2019 (last updated November 08, 2023)
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
0
Attacker Value
Unknown
CVE-2019-3900
Disclosure Date: April 25, 2019 (last updated April 27, 2024)
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
0
Attacker Value
Unknown
CVE-2019-11373
Disclosure Date: April 20, 2019 (last updated November 08, 2023)
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
0
Attacker Value
Unknown
CVE-2019-11372
Disclosure Date: April 20, 2019 (last updated November 08, 2023)
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
0
Attacker Value
Unknown
CVE-2018-16877
Disclosure Date: April 18, 2019 (last updated November 08, 2023)
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.
0