|
971
|
4.9
4.0
|
MEDIUM
Network
|
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged …
|
NVD-CWE-noinfo
|
CVE-2019-2580
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:41
2019-04-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
972
|
5.5
4.3
|
MEDIUM
Local
|
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to u…
|
CWE-754 CWE-908
Improper Check for Unusual or Exceptional Conditions Use of Uninitialized Resource
|
CVE-2019-11459
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:21
2019-04-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
973
|
5.9
5.8
|
MEDIUM
Network
|
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
|
CWE-59
Link Following
|
CVE-2019-3902
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
974
|
9.8
7.5
|
CRITICAL
Network
|
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
|
CWE-287
Improper Authentication
|
CVE-2019-11234
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:20
2019-04-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
975
|
9.8
7.5
|
CRITICAL
Network
|
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2019-11235
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 13:20
2019-04-22
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
976
|
7.5
5.0
|
HIGH
Network
|
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-10245
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:18
2019-04-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
977
|
5.5
2.1
|
MEDIUM
Local
|
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16878
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 12:53
2019-04-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
978
|
7.8
4.6
|
HIGH
Local
|
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknes…
|
NVD-CWE-noinfo
|
CVE-2018-16877
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 12:53
2019-04-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
979
|
7.5
5.0
|
HIGH
Network
|
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2019-3883
|
cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
980
|
6.5
3.3
|
MEDIUM
Adjacent
|
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
|
CWE-20
Improper Input Validation
|
CVE-2019-3460
|
cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 13:42
2019-04-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|