Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 536

Количество 55 536

redhat логотип

CVE-2019-20334

больше 6 лет назад

In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2019-20330

больше 6 лет назад

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2019-20326

больше 6 лет назад

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-2025

больше 7 лет назад

In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-116855682References: Upstream kernel

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2019-2024

больше 7 лет назад

In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111761954References: Upstream kernel

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2019-20218

больше 6 лет назад

selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-20149

больше 6 лет назад

ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2019-20096

больше 6 лет назад

In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2019-20095

больше 6 лет назад

mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82. This will cause a memory leak and denial of service.

CVSS3: 5.2
EPSS: Низкий
redhat логотип

CVE-2019-20079

почти 7 лет назад

The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-20054

больше 6 лет назад

In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2019-20044

больше 6 лет назад

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-19977

больше 6 лет назад

libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2019-19966

больше 6 лет назад

In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2019-19965

больше 6 лет назад

In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2019-19959

больше 6 лет назад

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2019-19956

больше 6 лет назад

xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-19952

больше 6 лет назад

In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2019-19949

больше 6 лет назад

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2019-19948

больше 6 лет назад

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

CVSS3: 7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-20334

In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects the relationships among expr0, expr1, expr2, expr3, expr4, expr5, and expr6 (and stdscan in asm/stdscan.c). This is similar to CVE-2019-6290 and CVE-2019-6291.

CVSS3: 6.2
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20330

FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

CVSS3: 8.1
9%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20326

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.

CVSS3: 7.8
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-2025

In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-116855682References: Upstream kernel

CVSS3: 5.1
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-2024

In em28xx_unregister_dvb of em28xx-dvb.c, there is a possible use after free issue. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111761954References: Upstream kernel

CVSS3: 4.7
0%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-20218

selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.

CVSS3: 7.5
4%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20149

ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

CVSS3: 5.9
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20096

In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20095

mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handling cases that did not free allocated hostcmd memory, aka CID-003b686ace82. This will cause a memory leak and denial of service.

CVSS3: 5.2
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20079

The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.

CVSS3: 7.8
2%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-20054

In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links, aka CID-23da9588037e.

CVSS3: 5.1
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-20044

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19977

libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.

CVSS3: 7.4
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19966

In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19965

In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

CVSS3: 4.7
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19959

ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' characters in filenames, leading to a memory-management error that can be detected by (for example) valgrind.

CVSS3: 7.3
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19956

xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.

CVSS3: 7.5
6%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19952

In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to ReadOneMNGImage.

CVSS3: 7
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19949

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.

CVSS3: 3.3
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-19948

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

CVSS3: 7
4%
Низкий
больше 6 лет назад

Уязвимостей на страницу