|
225611
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux kernel before 5.3.5 allow attackers to cause a denial of service (memory consumpt…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-18807
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225612
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel before 5.3.5 allows local users to cause a denial of service (memory consumption) b…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-18806
|
2024-11-21 13:33 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225613
|
7.5 |
HIGH
Network
|
djvulibre_project debian fedoraproject canonical opensuse
|
djvulibre debian_linux fedora ubuntu_linux leap
|
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18804
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225614
|
9.8 |
CRITICAL
Network
|
linux opensuse redhat netapp broadcom
|
linux_kernel leap enterprise_linux steelstore_cloud_integrated_storage data_availability_services solidfire hci_management_node hci_storage_node active_iq_unified_manager f…
|
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very l…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-18805
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225615
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_adselfservice_plus
|
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled informati…
|
CWE-352
Origin Validation Error
|
CVE-2019-18411
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225616
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
|
CWE-476
NULL Pointer Dereference
|
CVE-2019-18799
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225617
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2019-18798
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225618
|
6.5 |
MEDIUM
Network
|
sass-lang
|
libsass
|
LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
|
CWE-674
Uncontrolled Recursion
|
CVE-2019-18797
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225619
|
8.8 |
HIGH
Network
|
rakuten
|
viber
|
Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber protocol traffic is encrypted. TCP data packet 9 on por…
|
CWE-311 CWE-319
Missing Encryption of Sensitive Data Cleartext Transmission of Sensitive Information
|
CVE-2019-18800
|
2024-11-21 13:33 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225620
|
5.5 |
MEDIUM
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could cause a memory disclosure problem.
|
CWE-908
Use of Uninitialized Resource
|
CVE-2019-18786
|
2024-11-21 13:33 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|