|
222211
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cp…
|
CWE-416
Use After Free
|
CVE-2019-19768
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222212
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext…
|
CWE-416
Use After Free
|
CVE-2019-19767
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222213
|
7.5 |
HIGH
Network
|
bitwarden
|
server
|
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2019-19766
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222214
|
9.8 |
CRITICAL
Network
|
minerstat
|
msos
|
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
|
NVD-CWE-noinfo
|
CVE-2019-19750
|
2024-11-21 13:35 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222215
|
6.1 |
MEDIUM
Network
|
brizoit
|
work_time_calendar
|
The Work Time Calendar app before 4.7.1 for Jira allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-19748
|
2024-11-21 13:35 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222216
|
5.5 |
MEDIUM
Local
|
fig2dev_project fedoraproject
|
fig2dev fedora
|
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-19746
|
2024-11-21 13:35 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222217
|
9.8 |
CRITICAL
Network
|
octeth
|
oempro
|
Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
|
CWE-89
SQL Injection
|
CVE-2019-19740
|
2024-11-21 13:35 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222218
|
7.8 |
HIGH
Local
|
openbsd
|
openbsd
|
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be defeated by setting a very small RLIMIT_DATA resource limit. When executing ch…
|
CWE-269
Improper Privilege Management
|
CVE-2019-19726
|
2024-11-21 13:35 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222219
|
7.5 |
HIGH
Network
|
bson-objectid_project
|
bson-objectid
|
An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacker to generate a malformed objectid by inserting an additional property to the u…
|
CWE-670
Always-Incorrect Control Flow Implementation
|
CVE-2019-19729
|
2024-11-21 13:35 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222220
|
9.8 |
CRITICAL
Network
|
sysstat_project debian canonical
|
sysstat debian_linux ubuntu_linux
|
sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
|
CWE-415
Double Free
|
CVE-2019-19725
|
2024-11-21 13:35 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|