Количество 25 045
Количество 25 045
CVE-2019-19906
CVE-2019-19847
Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.
CVE-2019-19646
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
CVE-2019-19645
alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements.
CVE-2019-19391
In LuaJIT through 2.0.5 as used in Moonjit before 2.1.2 and other products debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT project owner states that the debug libary is unsafe by definition and that this is not a vulnerability. When LuaJIT was originally developed the expectation was that the entire debug library had no security guarantees and thus it made no sense to assign CVEs. However not all users of later LuaJIT derivatives share this perspective
CVE-2019-19338
CVE-2019-19317
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2019-19126
CVE-2019-19076
A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption) aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted
CVE-2019-18874
CVE-2019-18368
In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
CVE-2019-18348
CVE-2019-18276
CVE-2019-18222
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
CVE-2019-17596
CVE-2019-17567
mod_proxy_wstunnel tunneling of non Upgraded connections
CVE-2019-17498
CVE-2019-17455
CVE-2019-17451
CVE-2019-17450
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 7.5 | 8% Низкий | почти 6 лет назад | ||
CVE-2019-19847 Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c. | CVSS3: 8.1 | 1% Низкий | больше 4 лет назад | |
CVE-2019-19646 pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns. | CVSS3: 9.8 | 5% Низкий | 5 месяцев назад | |
CVE-2019-19645 alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements. | CVSS3: 5.5 | 1% Низкий | 6 месяцев назад | |
CVE-2019-19391 In LuaJIT through 2.0.5 as used in Moonjit before 2.1.2 and other products debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT project owner states that the debug libary is unsafe by definition and that this is not a vulnerability. When LuaJIT was originally developed the expectation was that the entire debug library had no security guarantees and thus it made no sense to assign CVEs. However not all users of later LuaJIT derivatives share this perspective | CVSS3: 9.1 | 1% Низкий | около 2 лет назад | |
CVSS3: 5.5 | 0% Низкий | почти 6 лет назад | ||
CVE-2019-19317 lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact. | 4% Низкий | 11 месяцев назад | ||
CVSS3: 3.3 | 0% Низкий | почти 6 лет назад | ||
CVE-2019-19076 A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption) aka CID-78beef629fd9. NOTE: This has been argued as not a valid vulnerability. The upstream commit 78beef629fd9 was reverted | CVSS3: 5.9 | 3% Низкий | 6 месяцев назад | |
CVSS3: 7.5 | 4% Низкий | около 5 лет назад | ||
CVE-2019-18368 In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. | CVSS3: 7.3 | 1% Низкий | 10 месяцев назад | |
CVSS3: 6.1 | 4% Низкий | больше 5 лет назад | ||
CVSS3: 7.8 | 3% Низкий | почти 6 лет назад | ||
CVE-2019-18222 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks. | 0% Низкий | 11 месяцев назад | ||
CVSS3: 7.5 | 5% Низкий | почти 2 года назад | ||
CVE-2019-17567 mod_proxy_wstunnel tunneling of non Upgraded connections | CVSS3: 5.3 | 60% Средний | около 5 лет назад | |
CVSS3: 8.1 | 4% Низкий | почти 6 лет назад | ||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 6.5 | 2% Низкий | почти 6 лет назад | ||
CVSS3: 6.5 | 3% Низкий | почти 6 лет назад |
Уязвимостей на страницу