Show filters
416 Total Results
Displaying 131-140 of 416
Sort by:
Attacker Value
Unknown
CVE-2019-14861
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer.
0
Attacker Value
Unknown
CVE-2019-13753
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13734
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13752
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13750
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Insufficient data validation in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass defense-in-depth measures via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2019-13751
Disclosure Date: December 10, 2019 (last updated November 08, 2023)
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2012-4428
Disclosure Date: December 02, 2019 (last updated November 27, 2024)
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
0
Attacker Value
Unknown
CVE-2019-14901
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with this vulnerability is with the availability of the system. If code execution occurs, the code will run with the permissions of root. This will affect both confidentiality and integrity of files on the system.
0
Attacker Value
Unknown
CVE-2019-14895
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-18660
Disclosure Date: November 27, 2019 (last updated November 08, 2023)
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
0