CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2019-19066

    Last Modified: 21 Nov 2024

    A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.

    Published: 18 Nov 2019
    4.7
    Medium

    CVE-2019-19065

    Last Modified: 21 Nov 2024

    A memory leak in the sdma_init() function in drivers/infiniband/hw/hfi1/sdma.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering rhashtable_init() failures, aka CID-34b3be18a04e. NOTE: This has been disputed as not a vulnerability because "rhashtable_init() can only fail if it is passed invalid values in the second parameter's struct, but when invoked from sdma_init() that is a pointer to a static const struct, so an attacker could only trigger failure if they could corrupt kernel memory (in which case a small memory leak is not a significant problem).

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19064

    Last Modified: 5 May 2025

    A memory leak in the fsl_lpspi_probe() function in drivers/spi/spi-fsl-lpspi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering pm_runtime_get_sync() failures, aka CID-057b8945f78f. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control these failures at probe time

    Published: 18 Nov 2019
    4.6
    Medium

    CVE-2019-19063

    Last Modified: 21 Nov 2024

    Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.

    Published: 18 Nov 2019
    4.7
    Medium

    CVE-2019-19062

    Last Modified: 21 Nov 2024

    A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19061

    Last Modified: 21 Nov 2024

    A memory leak in the adis_update_scan_mode_burst() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-9c0530e898f3.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19060

    Last Modified: 21 Nov 2024

    A memory leak in the adis_update_scan_mode() function in drivers/iio/imu/adis_buffer.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-ab612b1daf41.

    Published: 18 Nov 2019
    4.7
    Medium

    CVE-2019-19059

    Last Modified: 21 Nov 2024

    Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/iwlwifi/pcie/ctxt-info-gen3.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering iwl_pcie_init_fw_sec() or dma_alloc_coherent() failures, aka CID-0f4f199443fa.

    Published: 18 Nov 2019
    4.7
    Medium

    CVE-2019-19058

    Last Modified: 21 Nov 2024

    A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.

    Published: 18 Nov 2019
    3.3
    Low

    CVE-2019-19057

    Last Modified: 21 Nov 2024

    Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.

    Published: 18 Nov 2019
    5.5
    Medium

    CVE-2019-19043

    Last Modified: 21 Nov 2024

    A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.

    Published: 18 Nov 2019
    6.5
    Medium

    CVE-2019-19046

    Last Modified: 21 Nov 2024

    A memory leak in the __ipmi_bmc_register() function in drivers/char/ipmi/ipmi_msghandler.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering ida_simple_get() failure, aka CID-4aa7afb0ee20. NOTE: third parties dispute the relevance of this because an attacker cannot realistically control this failure at probe time

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19048

    Last Modified: 21 Nov 2024

    A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19050

    Last Modified: 21 Nov 2024

    A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.

    Published: 18 Nov 2019
    5.5
    Medium

    CVE-2019-19051

    Last Modified: 21 Nov 2024

    A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19052

    Last Modified: 21 Nov 2024

    A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2019-20477

    Last Modified: 21 Nov 2024

    PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-10172

    Last Modified: 21 Nov 2024

    A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.

    Published: 18 Nov 2019
    9.8
    Critical

    CVE-2019-12409

    Last Modified: 21 Nov 2024

    The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.

    Published: 18 Nov 2019
    5.5
    Medium

    CVE-2019-19047

    Last Modified: 21 Nov 2024

    A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, aka CID-c7ed6d0183d5.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19044

    Last Modified: 21 Nov 2024

    Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-19049

    Last Modified: 7 Mar 2025

    A memory leak in the unittest_data_add() function in drivers/of/unittest.c in the Linux kernel before 5.3.10 allows attackers to cause a denial of service (memory consumption) by triggering of_fdt_unflatten_tree() failures, aka CID-e13de8fe0d6a. NOTE: third parties dispute the relevance of this because unittest.c can only be reached during boot

    Published: 18 Nov 2019
    5.5
    Medium

    CVE-2019-19338

    Last Modified: 21 Nov 2024

    A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affected by the TAA flaw (TAA_NO=0), but is not affected by the MDS issue (MDS_NO=1), the guest was to clear the affected buffers by using a VERW instruction mechanism. But when the MDS_NO=1 bit was exported to the guests, the guests did not use the VERW mechanism to clear the affected buffers. This issue affects guests running on Cascade Lake CPUs and requires that host has 'TSX' enabled. Confidentiality of data is the highest threat associated with this vulnerability.

    Published: 18 Nov 2019
    7.5
    High

    CVE-2019-12422

    Last Modified: 21 Nov 2024

    Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding attack.

    Published: 18 Nov 2019
    8.8
    High

    CVE-2019-13724

    Last Modified: 21 Nov 2024

    Out of bounds memory access in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Nov 2019
    5.5
    Medium

    CVE-2019-19036

    Last Modified: 21 Nov 2024

    btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_dereference(root->node) can be zero.

    Published: 18 Nov 2019
    5.5
    Medium

    CVE-2019-19037

    Last Modified: 21 Nov 2024

    ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can be zero.

    Published: 18 Nov 2019
    4.4
    Medium

    CVE-2019-19045

    Last Modified: 21 Nov 2024

    A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.

    Published: 18 Nov 2019
    8.8
    High

    CVE-2019-13723

    Last Modified: 21 Nov 2024

    Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 18 Nov 2019
    7.2
    High

    CVE-2019-19041

    Last Modified: 21 Nov 2024

    An issue was discovered in Xorux Lpar2RRD 6.11 and Stor2RRD 2.61, as distributed in Xorux 2.41. They do not correctly verify the integrity of an upgrade package before processing it. As a result, official upgrade packages can be modified to inject an arbitrary Bash script that will be executed by the underlying system. It is possible to achieve this by modifying the values in the files.SUM file (which are used for integrity control) and injecting malicious code into the upgrade.sh file.

    Published: 17 Nov 2019
    6.1
    Medium

    CVE-2019-19040

    Last Modified: 21 Nov 2024

    KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a '"sampling":{"value":"<script>' substring.

    Published: 17 Nov 2019
    5.5
    Medium

    CVE-2019-19035

    Last Modified: 21 Nov 2024

    jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgfile.c. The attack vector is: Open a specially crafted JPEG file.

    Published: 17 Nov 2019
    7.5
    High

    CVE-2019-19022

    Last Modified: 21 Nov 2024

    iTerm2 through 3.3.6 has potentially insufficient documentation about the presence of search history in com.googlecode.iterm2.plist, which might allow remote attackers to obtain sensitive information, as demonstrated by searching for the NoSyncSearchHistory string in .plist files within public Git repositories.

    Published: 17 Nov 2019
    9.8
    Critical

    CVE-2019-20788

    Last Modified: 21 Nov 2024

    libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.

    Published: 17 Nov 2019
    7.5
    High

    CVE-2019-19011

    Last Modified: 21 Nov 2024

    MiniUPnP ngiflib 0.4 has a NULL pointer dereference in GifIndexToTrueColor in ngiflib.c via a file that lacks a palette.

    Published: 16 Nov 2019
    9.8
    Critical

    CVE-2019-19010

    Last Modified: 21 Nov 2024

    Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.

    Published: 16 Nov 2019
    5.7
    Medium

    CVE-2019-16762

    Last Modified: 21 Nov 2024

    A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slpjs npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. Affected users can upgrade to any version >= 0.21.4.

    Published: 15 Nov 2019
    5.7
    Medium

    CVE-2019-16761

    Last Modified: 21 Nov 2024

    A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the [email protected] npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched.

    Published: 15 Nov 2019
    7.5
    High

    CVE-2019-6664

    Last Modified: 21 Nov 2024

    On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices.

    Published: 15 Nov 2019
    6.5
    Medium

    CVE-2019-6662

    Last Modified: 21 Nov 2024

    On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data.

    Published: 15 Nov 2019
    5.5
    Medium

    CVE-2019-6663

    Last Modified: 21 Nov 2024

    The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) attack.

    Published: 15 Nov 2019
    7.5
    High

    CVE-2019-6661

    Last Modified: 21 Nov 2024

    When the BIG-IP APM 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.4.1, or 11.5.1-11.6.5 system processes certain requests, the APD/APMD daemon may consume excessive resources.

    Published: 15 Nov 2019
    7.5
    High

    CVE-2019-6660

    Last Modified: 21 Nov 2024

    On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service.

    Published: 15 Nov 2019
    9.8
    Critical

    CVE-2019-13582

    Last Modified: 21 Nov 2024

    An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution.

    Published: 15 Nov 2019
    7.5
    High

    CVE-2019-6659

    Last Modified: 21 Nov 2024

    On version 14.0.0-14.1.0.1, BIG-IP virtual servers with TLSv1.3 enabled may experience a denial of service due to undisclosed incoming messages.

    Published: 15 Nov 2019
    9.8
    Critical

    CVE-2019-13581

    Last Modified: 21 Nov 2024

    An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service or execute arbitrary code via malformed Wi-Fi packets.

    Published: 15 Nov 2019
    7.8
    High

    CVE-2019-18372

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published: 15 Nov 2019
    7.8
    High

    CVE-2019-12759

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published: 15 Nov 2019
    6.7
    Medium

    CVE-2019-12758

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature.

    Published: 15 Nov 2019
    7.8
    High

    CVE-2019-12757

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection (SEP), prior to 14.2 RU2 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to 12.1 RU6 MP10d (12.1.7510.7002), may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published: 15 Nov 2019