Количество 18 769
Количество 18 769
CVE-2019-3887
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that L1 guest could access L0's APIC register values via L2 guest when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue.
CVE-2019-3886
CVE-2019-3870
CVE-2019-3844
CVE-2019-3843
CVE-2019-3842
CVE-2019-3833
CVE-2019-3832
CVE-2019-3819
A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable.
CVE-2019-3816
CVE-2019-3016
CVE-2019-2708
CVE-2019-25219
CVE-2019-25160
netlabel: fix out-of-bounds memory accesses
CVE-2019-25085
GNOME gvdb gvdb-builder.c gvdb_table_write_contents_async use after free
CVE-2019-25076
The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache aka a Tuple Space Explosion (TSE) attack.
CVE-2019-25058
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
CVE-2019-25051
CVE-2019-25013
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32 when processing invalid multi-byte input sequences in the EUC-KR encoding may have a buffer over-read.
CVE-2019-20916
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command because a Content-Disposition header can have ../ in a filename as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-3887 A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that L1 guest could access L0's APIC register values via L2 guest when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versions from 4.16 and newer are vulnerable to this issue. | CVSS3: 5.6 | 0% Низкий | больше 5 лет назад | |
CVSS3: 5.4 | 1% Низкий | больше 5 лет назад | ||
CVSS3: 6.1 | 0% Низкий | больше 1 года назад | ||
CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 7.8 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 7 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 7.5 | 1% Низкий | больше 1 года назад | ||
CVSS3: 5 | 0% Низкий | около 5 лет назад | ||
CVE-2019-3819 A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a denial of service. Versions from v4.18 and newer are vulnerable. | CVSS3: 4.4 | 0% Низкий | больше 5 лет назад | |
CVSS3: 7.5 | 1% Низкий | больше 1 года назад | ||
CVSS3: 4.7 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 3.3 | 1% Низкий | больше 4 лет назад | ||
CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | ||
CVE-2019-25160 netlabel: fix out-of-bounds memory accesses | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
CVE-2019-25085 GNOME gvdb gvdb-builder.c gvdb_table_write_contents_async use after free | 1% Низкий | 5 месяцев назад | ||
CVE-2019-25076 The TSS (Tuple Space Search) algorithm in Open vSwitch 2.x through 2.17.2 and 3.0.0 allows remote attackers to cause a denial of service (delays of legitimate traffic) via crafted packet data that requires excessive evaluation time within the packet classification algorithm for the MegaFlow cache aka a Tuple Space Explosion (TSE) attack. | CVSS3: 5.8 | 1% Низкий | больше 3 лет назад | |
CVE-2019-25058 An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running an unprivileged user could make USBGuard allow all USB devices to be connected in the future. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | ||
CVE-2019-25013 The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32 when processing invalid multi-byte input sequences in the EUC-KR encoding may have a buffer over-read. | CVSS3: 5.9 | 1% Низкий | около 5 лет назад | |
CVE-2019-20916 The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command because a Content-Disposition header can have ../ in a filename as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py. | CVSS3: 7.5 | 1% Низкий | около 5 лет назад |
Уязвимостей на страницу