CVE-2019-0113
published 2019-05-17CVE-2019-0113: Insufficient bounds checking in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an…
PriorityP417medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.34%
25.8th percentile
Insufficient bounds checking in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9g8p-pq33-qfrc: Insufficient bounds checking in Intel(R) Graphics Drivers before version 10
ghsa_unreviewed·2022-05-24
CVE-2019-0113 [MEDIUM] CWE-119 GHSA-9g8p-pq33-qfrc: Insufficient bounds checking in Intel(R) Graphics Drivers before version 10
Insufficient bounds checking in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.
Red Hat
struts2: Struts internals manipulation via cookie request headers
vendor_redhat·2014-05-05·CVSS 7.5
CVE-2014-0116 [HIGH] struts2: Struts internals manipulation via cookie request headers
struts2: Struts internals manipulation via cookie request headers
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included
Red Hat
struts2: ClassLoader manipulation via cookie request headers
vendor_redhat·2014-04-25·CVSS 5.0
CVE-2014-0113 [MEDIUM] struts2: ClassLoader manipulation via cookie request headers
struts2: ClassLoader manipulation via cookie request headers
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in som
No detection rules found.
No public exploits indexed.
2019-05-17
Published