Show filters
213 Total Results
Displaying 61-70 of 213
Sort by:
Attacker Value
Unknown

CVE-2019-5804

Disclosure Date: May 23, 2019 (last updated November 08, 2023)
Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name.
Attacker Value
Unknown

CVE-2019-12098

Disclosure Date: May 15, 2019 (last updated November 08, 2023)
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
Attacker Value
Unknown

CVE-2019-8936

Disclosure Date: May 15, 2019 (last updated November 08, 2023)
NTP through 4.2.8p12 has a NULL Pointer Dereference.
Attacker Value
Unknown

CVE-2019-11884

Disclosure Date: May 10, 2019 (last updated November 08, 2023)
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
Attacker Value
Unknown

CVE-2019-11815

Disclosure Date: May 08, 2019 (last updated November 27, 2024)
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.
Attacker Value
Unknown

CVE-2018-19456

Disclosure Date: May 07, 2019 (last updated November 27, 2024)
The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql.
0
Attacker Value
Unknown

CVE-2019-7443

Disclosure Date: May 07, 2019 (last updated November 08, 2023)
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.
0
Attacker Value
Unknown

Heap over-read in PHP EXIF extension

Disclosure Date: May 03, 2019 (last updated November 08, 2023)
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
Attacker Value
Unknown

CVE-2019-11627

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
Attacker Value
Unknown

CVE-2019-10131

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.