|
222641
|
9.8 |
CRITICAL
Network
|
fasterxml debian fedoraproject redhat netapp oracle
|
jackson-databind debian_linux fedora jboss_enterprise_application_platform steelstore_cloud_integrated_storage oncommand_workflow_automation service_level_manager oncommand_api_s…
|
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-16942
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222642
|
5.5 |
MEDIUM
Local
|
glyphandcog
|
xpdfreader
|
Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-17064
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222643
|
5.5 |
MEDIUM
Local
|
snowtide
|
pdfxstream
|
In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation because of page-tree mishandling.
|
NVD-CWE-noinfo
|
CVE-2019-17063
|
2024-11-21 13:31 |
2019-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222644
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka C…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17056
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222645
|
3.3 |
LOW
Local
|
linux debian fedoraproject canonical opensuse redhat
|
linux_kernel debian_linux fedora ubuntu_linux leap enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw sock…
|
CWE-862
Missing Authorization
|
CVE-2019-17055
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222646
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17054
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222647
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw s…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17053
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222648
|
3.3 |
LOW
Local
|
linux debian fedoraproject canonical
|
linux_kernel debian_linux fedora ubuntu_linux
|
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka C…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-17052
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222649
|
7.5 |
HIGH
Network
|
rust-lang
|
rust
|
Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration key. Usage of the `package` key to rename dependencies in `Cargo.toml` is ignor…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2019-16760
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222650
|
7.8 |
HIGH
Local
|
evernote
|
evernote
|
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop ope…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-17051
|
2024-11-21 13:31 |
2019-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|