Show filters
197 Total Results
Displaying 101-110 of 197
Sort by:
Attacker Value
Unknown

CVE-2019-13313

Disclosure Date: July 05, 2019 (last updated November 08, 2023)
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
Attacker Value
Unknown

CVE-2019-12817

Disclosure Date: June 25, 2019 (last updated November 08, 2023)
arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.
Attacker Value
Unknown

CVE-2019-10126

Disclosure Date: June 14, 2019 (last updated November 27, 2024)
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.
Attacker Value
Unknown

CVE-2019-9755

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where /bin/ntfs-3g is a setuid-root binary, this could lead to a local escalation of privileges.
Attacker Value
Unknown

CVE-2019-11356

Disclosure Date: June 03, 2019 (last updated November 08, 2023)
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
Attacker Value
Unknown

CVE-2019-12450

Disclosure Date: May 29, 2019 (last updated November 08, 2023)
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
Attacker Value
Unknown

CVE-2019-0820

Disclosure Date: May 16, 2019 (last updated November 27, 2024)
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
Attacker Value
Unknown

CVE-2019-11833

Disclosure Date: May 15, 2019 (last updated November 08, 2023)
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
Attacker Value
Unknown

CVE-2019-11884

Disclosure Date: May 10, 2019 (last updated November 08, 2023)
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
Attacker Value
Unknown

CVE-2019-9810

Disclosure Date: April 26, 2019 (last updated November 27, 2024)
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.