|
213451
|
8.1 |
HIGH
Network
|
linux debian canonical f5 redhat
|
linux_kernel debian_linux ubuntu_linux big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy…
|
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2019-6974
|
2024-11-21 13:47 |
2019-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213452
|
7.5 |
HIGH
Network
|
djangoproject canonical fedoraproject
|
django ubuntu_linux fedora
|
Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() func…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-6975
|
2024-11-21 13:47 |
2019-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213453
|
9.8 |
CRITICAL
Network
|
css-tricks
|
chat2
|
An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection vulnerability.
|
CWE-89
SQL Injection
|
CVE-2019-7316
|
2024-11-21 13:47 |
2019-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213454
|
9.8 |
CRITICAL
Network
|
live555 debian
|
streaming_media debian_linux
|
liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server…
|
CWE-416
Use After Free
|
CVE-2019-7314
|
2024-11-21 13:47 |
2019-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213455
|
6.1 |
MEDIUM
Network
|
buildbot
|
buildbot
|
www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout via the redirect parameter. This affects other web sites in the same domain.
|
CWE-93
CRLF Injection
|
CVE-2019-7313
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213456
|
5.3 |
MEDIUM
Network
|
primx
|
zed zedmail zonecentral
|
Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) before 6.1.2150, Zed Entreprise for Mac before 2.0…
|
CWE-200
Information Exposure
|
CVE-2019-7312
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213457
|
7.8 |
HIGH
Local
|
freedesktop canonical debian fedoraproject redhat
|
poppler ubuntu_linux debian_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux enterprise_linux_eus enterprise_linu…
|
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash…
|
CWE-125 CWE-681
Out-of-bounds Read Incorrect Conversion between Numeric Types
|
CVE-2019-7310
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213458
|
5.5 |
MEDIUM
Local
|
gnu
|
glibc
|
In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significan…
|
NVD-CWE-noinfo
|
CVE-2019-7309
|
2024-11-21 13:47 |
2019-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213459
|
5.6 |
MEDIUM
Local
|
linux canonical opensuse
|
linux_kernel ubuntu_linux leap
|
kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different sta…
|
CWE-189
Numeric Errors
|
CVE-2019-7308
|
2024-11-21 13:47 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213460
|
7.2 |
HIGH
Network
|
zevenet
|
zen_load_balancer
|
Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter.
|
CWE-78
OS Command
|
CVE-2019-7301
|
2024-11-21 13:47 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|