BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.
Apache Xerces-C could allow a remote attacker to execute arbitrary code on the system, caused by an use-after-free error during the scanning of external DTDs. By sending a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102886
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An uninitialized use flaw was found in the rendering component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101852
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient validation of untrusted input flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=101195
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An integer overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102089
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102546
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102381
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102886
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102475
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the WebSockets component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102548
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
A heap buffer overflow flaw was found in the password manager component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102715
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An insufficient policy enforcement flaw was found in the WebSockets component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=944619
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
An use after free flaw was found in the Bluetooth component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=102506
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.
Last updated 24 July 2024
Last updated 24 July 2024
It was discovered that libvirtd would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would execute an arbitrary program when the domain was resumed.
This vulnerability was first present in libvirt v3.6.1.
Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
IBM JDK 7 SR10 FP45 (7.0.10.45), 7.1 SR4 FP45 (7.1.4.45), and 8 SR5 FP35 (8.0.5.35) fix a flaw described by upstream as:
Eclipse OpenJ9 is vulnerable to a denial of service, caused by the execution of a method past the end of bytecode array by the Java bytecode verifier. A remote attacker could exploit this vulnerability to cause the application to crash.
OpenJ9 upstream bug:
https://bugs.eclipse.org/bugs/showbug.cgi?id=545588
OpenJ9 upstream merge requests:
https://github.com/eclipse/openj9/pull/5528 https://github.com/eclipse/openj9/pull/5529
References:
https://www-01.ibm.com/support/docview.wss?uid=ibm10882850 https://developer.ibm.com/javasdk/support/security-vulnerabilities/#IBMSecurityUpdateApril2019
A double-free can happen in idrremoveall() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
An off-by-one error was found in spice when accessing arrays. A malicious guest user can use this for a host denial of service.
A type confusion flaw was found in the SVG component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=915469
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An insufficient validation of untrusted input flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=914731
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An use after free flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=913970
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An insufficient validation of untrusted input flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=913975
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=913296
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An use after free flaw was found in the WebRTC component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=913246
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
An out of bounds read flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=907714
External References:
https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html