|
223031
|
6.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration is mishandled. In a number of places bitmaps are b…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2019-19582
|
2024-11-21 13:34 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223032
|
6.5 |
MEDIUM
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2019-19581
|
2024-11-21 13:34 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223033
|
6.6 |
MEDIUM
Network
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an inc…
|
CWE-362
Race Condition
|
CVE-2019-19580
|
2024-11-21 13:34 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223034
|
8.8 |
HIGH
Local
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "…
|
CWE-682
Incorrect Calculation
|
CVE-2019-19578
|
2024-11-21 13:34 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223035
|
7.2 |
HIGH
Physics
|
xen fedoraproject
|
xen fedora
|
An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possibly gain privileges by triggering data-structure access during pagetable-height …
|
CWE-401 CWE-662
Missing Release of Memory after Effective Lifetime Improper Synchronization
|
CVE-2019-19577
|
2024-11-21 13:34 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223036
|
5.3 |
MEDIUM
Network
|
last.fm
|
last.fm_desktop
|
The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without the use of SSL/TLS. Although there is an Enable SSL option, it is disabled by d…
|
CWE-1188 CWE-319
Insecure Default Initialization of Resource Cleartext Transmission of Sensitive Information
|
CVE-2019-19251
|
2024-11-21 13:34 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223037
|
9.8 |
CRITICAL
Network
|
broadcom
|
nolio
|
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-19230
|
2024-11-21 13:34 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223038
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-19449
|
2024-11-21 13:34 |
2019-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223039
|
7.8 |
HIGH
Local
|
linux debian canonical netapp
|
linux_kernel debian_linux ubuntu_linux cloud_backup steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node active_iq_unified_manager a…
|
In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space…
|
CWE-416
Use After Free
|
CVE-2019-19448
|
2024-11-21 13:34 |
2019-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223040
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup steelstore_cloud_integrated_storage data_availability_services active_iq_unified_manager solidfire_baseboard_management_controller hci_baseboard_management…
|
In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orp…
|
CWE-416
Use After Free
|
CVE-2019-19447
|
2024-11-21 13:34 |
2019-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|