Total
12074 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-16093 | 2 Canonical, Symonics | 2 Ubuntu Linux, Libmysofa | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c. | |||||
CVE-2019-15943 | 1 Valvesoftware | 1 Counter-strike\ | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a memset call. | |||||
CVE-2019-15938 | 1 Pengutronix | 1 Barebox | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy. | |||||
CVE-2019-15937 | 1 Pengutronix | 1 Barebox | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy. | |||||
CVE-2019-15767 | 1 Gnu | 1 Chess | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file. | |||||
CVE-2019-15695 | 2 Opensuse, Tigervnc | 2 Leap, Tigervnc | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of PixelFormat. Since remote attacker can choose offset from start of the buffer to start writing his values, exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity. | |||||
CVE-2019-15694 | 2 Opensuse, Tigervnc | 2 Leap, Tigervnc | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing MemOutStream. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity. | |||||
CVE-2019-15693 | 1 Tigervnc | 1 Tigervnc | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity. | |||||
CVE-2019-15692 | 2 Opensuse, Tigervnc | 2 Leap, Tigervnc | 2024-11-21 | 6.5 MEDIUM | 7.2 HIGH |
TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability could potentially result into remote code execution. This attack appear to be exploitable via network connectivity. | |||||
CVE-2019-15683 | 1 Turbovnc | 1 Turbovnc | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly result into remote code execution, since stack frame is not protected with stack canary. This attack appear to be exploitable via network connectivity. To exploit this vulnerability authorization on server is required. These issues have been fixed in commit cea98166008301e614e0d36776bf9435a536136e. | |||||
CVE-2019-15679 | 1 Tightvnc | 1 Tightvnc | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially result code execution. This attack appear to be exploitable via network connectivity. | |||||
CVE-2019-15678 | 1 Tightvnc | 1 Tightvnc | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result code execution.. This attack appear to be exploitable via network connectivity. | |||||
CVE-2019-15665 | 1 Killernetworking | 1 Killer Control Center | 2024-11-21 | 9.0 HIGH | 7.2 HIGH |
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate an offset passed as a parameter during a memory operation, leading to an arbitrary write primitive that can lead to code execution or escalation of privileges. | |||||
CVE-2019-15661 | 1 Killernetworking | 1 Killer Control Center | 2024-11-21 | 9.0 HIGH | 7.2 HIGH |
An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to validate parameters, leading to a stack-based buffer overflow, which can lead to code execution or escalation of privileges. | |||||
CVE-2019-15554 | 1 Servo | 1 Smallvec | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity. | |||||
CVE-2019-15543 | 1 Slice-deque Project | 1 Slice-deque | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases. | |||||
CVE-2019-15540 | 1 Cdemu | 1 Libmirage | 2024-11-21 | 7.2 HIGH | 7.8 HIGH |
filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux user. | |||||
CVE-2019-15148 | 1 Gopro | 1 Gpmf-parser | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c. | |||||
CVE-2019-15048 | 1 Axiosys | 1 Bento4 | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4RtpAtom.cpp. | |||||
CVE-2019-14970 | 2 Debian, Videolan | 2 Debian Linux, Vlc Media Player | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file. |