Show filters
4,245 Total Results
Displaying 821-830 of 4,245
Sort by:
Attacker Value
Unknown
CVE-2012-3543
Disclosure Date: November 21, 2019 (last updated November 27, 2024)
mono 2.10.x ASP.NET Web Form Hash collision DoS
0
Attacker Value
Unknown
CVE-2019-19039
Disclosure Date: November 21, 2019 (last updated November 08, 2023)
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team disputes this issues as not being a vulnerability because “1) The kernel provide facilities to restrict access to dmesg - dmesg_restrict=1 sysctl option. So it's really up to the system administrator to judge whether dmesg access shall be disallowed or not. 2) WARN/WARN_ON are widely used macros in the linux kernel. If this CVE is considered valid this would mean there are literally thousands CVE lurking in the kernel - something which clearly is not the case.
0
Attacker Value
Unknown
CVE-2015-3166
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
0
Attacker Value
Unknown
CVE-2015-3167
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
0
Attacker Value
Unknown
CVE-2015-1607
Disclosure Date: November 20, 2019 (last updated November 08, 2023)
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."
0
Attacker Value
Unknown
CVE-2019-3466
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
0
Attacker Value
Unknown
CVE-2019-19126
Disclosure Date: November 19, 2019 (last updated November 08, 2023)
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
0
Attacker Value
Unknown
CVE-2019-19067
Disclosure Date: November 18, 2019 (last updated November 08, 2023)
Four memory leaks in the acp_hw_init() function in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices() or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute the relevance of this because the attacker must already have privileges for module loading
0
Attacker Value
Unknown
CVE-2019-19074
Disclosure Date: November 18, 2019 (last updated November 08, 2023)
A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.
0
Attacker Value
Unknown
CVE-2019-19062
Disclosure Date: November 18, 2019 (last updated November 08, 2023)
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
0