CVE-2019-0003
published 2019-01-15CVE-2019-0003: When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
1.97%
78.4th percentile
When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, a reachable assertion failure occurs, causing the routing protocol daemon (rpd) process to crash with a core file being generated. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 15.1 versions prior to 15.1R3; 15.1F versions prior to 15.1F3; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX2300/EX3400.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
| juniper | junos | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3jqv-j83m-6qhf: When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec confi
ghsa_unreviewed·2022-05-13
CVE-2019-0003 [MEDIUM] CWE-617 GHSA-3jqv-j83m-6qhf: When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec confi
When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, a reachable assertion failure occurs, causing the routing protocol daemon (rpd) process to crash with a core file being generated. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 15.1 versions prior to 15.1R3; 15.1F versions prior to 15.1F3; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15.1X53-D59 on EX
Juniper
CVE-2019-0003: When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec confi
vendor_juniper·2019-01-15·CVSS 5.9
CVE-2019-0003 [MEDIUM] CWE-617 CVE-2019-0003: When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec confi
CVE-2019-0003: When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, a reachable assertion failure occurs, causing the routing protocol daemon (rpd) process to crash with a core file being generated. Affected releases are Juniper Networks Junos OS: 12.1X46 versions prior to 12.1X46-D77 on SRX Series; 12.3 versions prior to 12.3R12-S10; 12.3X48 versions prior to 12.3X48-D70 on SRX Series; 14.1X53 versions prior to 14.1X53-D47 on EX2200/VC, EX3200, EX3300/VC, EX4200, EX4300, EX4550/VC, EX4600, EX6200, EX8200/VC (XRE), QFX3500, QFX3600, QFX5100; 15.1 versions prior to 15.1R3; 15.1F versions prior to 15.1F3; 15.1X49 versions prior to 15.1X49-D140 on SRX Series; 15.1X53 versions prior to 15
Suricata
GPL RPC tooltalk UDP overflow attempt
suricata·2010-09-23
CVE-1999-0003 GPL RPC tooltalk UDP overflow attempt
GPL RPC tooltalk UDP overflow attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL RPC tooltalk UDP overflow attempt"; content:"|00 01 86 F3|"; depth:4; offset:12; content:"|00 00 00 07|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; byte_test:4,>,128,0,relative; content:"|00 00 00 00|"; depth:4; offset:4; reference:bugtraq,122; reference:cve,1999-0003; classtype:misc-attack; sid:2101964; rev:9; metadata:created_at 2010_09_23, cve CVE_1999_0003, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
GPL RPC portmap ttdbserv request UDP
suricata·2010-09-23
CVE-1999-0003 GPL RPC portmap ttdbserv request UDP
GPL RPC portmap ttdbserv request UDP
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 111 (msg:"GPL RPC portmap ttdbserv request UDP"; content:"|00 01 86 A0|"; depth:4; offset:12; content:"|00 00 00 03|"; within:4; distance:4; byte_jump:4,4,relative,align; byte_jump:4,4,relative,align; content:"|00 01 86 F3|"; within:4; content:"|00 00 00 00|"; depth:4; offset:4; reference:arachnids,24; reference:bugtraq,122; reference:bugtraq,3382; reference:cve,1999-0003; reference:cve,1999-0687; reference:cve,1999-1075; reference:cve,2001-0717; reference:url,www.cert.org/advisories/CA-2001-05.html; classtype:rpc-portmap-decode; sid:2100588; rev:18; metadata:created_at 2010_09_23, cve CVE_1999_0003, signature_severity Informational, updated_at 2019_07_26;)
No public exploits indexed.
Bugzilla
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8619 [HIGH] CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8619 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8619
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8622 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8622 [HIGH] CVE-2019-8622 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8622 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8622
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8610 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8610 [HIGH] CVE-2019-8610 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8610 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8610
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8594 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8594 [HIGH] CVE-2019-8594 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8594 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8594
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8597 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 6.5
CVE-2019-8597 [MEDIUM] CVE-2019-8597 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8597 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8597
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8587 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8587 [HIGH] CVE-2019-8587 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8587 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8587
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8611 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8611 [HIGH] CVE-2019-8611 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8611 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8611
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-6237 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-6237 [HIGH] CVE-2019-6237 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-6237 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-6237
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8607 webkitgtk: Out-of-bounds read leading to memory disclosure
bugzilla·2020-09-08·CVSS 6.5
CVE-2019-8607 [MEDIUM] CVE-2019-8607 webkitgtk: Out-of-bounds read leading to memory disclosure
CVE-2019-8607 webkitgtk: Out-of-bounds read leading to memory disclosure
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8607
Processing maliciously crafted web content may result in the disclosure of process memory. An out-of-bounds read was addressed with improved input validation.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-8607
Bugzilla
CVE-2019-8601 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8601 [HIGH] CVE-2019-8601 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8601 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8601
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8596 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8596 [HIGH] CVE-2019-8596 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8596 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8596
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8609 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8609 [HIGH] CVE-2019-8609 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8609 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8609
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8586 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8586 [HIGH] CVE-2019-8586 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8586 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8586
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8623 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8623 [HIGH] CVE-2019-8623 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8623 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8623
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8608 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 6.3
CVE-2019-8608 [MEDIUM] CVE-2019-8608 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8608 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8608
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8595 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8595 [HIGH] CVE-2019-8595 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8595 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8595
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8584 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8584 [HIGH] CVE-2019-8584 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8584 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8584
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8615 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 6.5
CVE-2019-8615 [MEDIUM] CVE-2019-8615 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8615 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8615
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8583 [HIGH] CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8583 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8583
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-8571 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-08·CVSS 8.8
CVE-2019-8571 [HIGH] CVE-2019-8571 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8571 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0003 describes the following issue:
CVE-2019-8571
Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK and WPE WebKit before 2.24.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0003.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/c
Bugzilla
CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003) [epel-all]
bugzilla·2019-01-21·CVSS 6.1
CVE-2019-3810 [MEDIUM] CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003) [epel-all]
CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003)
bugzilla·2019-01-21·CVSS 6.1
CVE-2019-3810 [MEDIUM] CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003)
CVE-2019-3810 moodle: User full name is not escaped in the un-linked userpix page (MSA-19-0003)
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
References:
https://moodle.org/mod/forum/discuss.php?d=381230#p1536767
Upstream Patch:
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64372
Discussion:
Created moodle tracking bugs for this issue:
Affects: epel-all [bug 1668074]
2019-01-15
Published