|
222221
|
9.8 |
CRITICAL
Network
|
putty
|
putty
|
PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the same port to steal an incoming connection.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-17067
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222222
|
9.8 |
CRITICAL
Network
|
fasterxml debian fedoraproject redhat oracle netapp
|
jackson-databind debian_linux fedora jboss_enterprise_application_platform banking_platform jd_edwards_enterpriseone_tools primavera_gateway weblogic_server webcenter_portal
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16943
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222223
|
9.8 |
CRITICAL
Network
|
fasterxml debian fedoraproject redhat netapp oracle
|
jackson-databind debian_linux fedora jboss_enterprise_application_platform steelstore_cloud_integrated_storage oncommand_workflow_automation service_level_manager oncommand_api_s…
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16942
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222224
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17064
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222225
|
5.5 |
MEDIUM
Local
|
snowtide
|
pdfxstream
|
In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.
|
NVD-CWE-noinfo
|
CVE-2019-17063
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222226
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka C…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17056
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222227
|
3.3 |
LOW
Local
|
linux debian fedoraproject canonical opensuse redhat
|
linux_kernel debian_linux fedora ubuntu_linux leap enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw sock…
|
CWE-862
Missing Authorization
|
CVE-2019-17055
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222228
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17054
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222229
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw s…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17053
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222230
|
3.3 |
LOW
Local
|
linux debian fedoraproject canonical
|
linux_kernel debian_linux fedora ubuntu_linux
|
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka C…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17052
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|