CVE-2019-0114
published 2019-05-17CVE-2019-0114: A race condition in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated…
PriorityP414medium4.7CVSS 3.0
AVLACHPRLUINSUCNINAH
EPSS
0.22%
12.8th percentile
A race condition in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-633x-c6p5-r6w2: A race condition in Intel(R) Graphics Drivers before version 10
ghsa_unreviewed·2022-05-24
CVE-2019-0114 [MEDIUM] CWE-362 GHSA-633x-c6p5-r6w2: A race condition in Intel(R) Graphics Drivers before version 10
A race condition in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.
Red Hat
JON: struts1 reversion of fix for CVE-2014-0114
vendor_redhat·2019-10-02·CVSS 7.5
CVE-2019-3834 [HIGH] CWE-470 JON: struts1 reversion of fix for CVE-2014-0114
JON: struts1 reversion of fix for CVE-2014-0114
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3.
It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vul
No detection rules found.
No public exploits indexed.
arXiv
Leveraging Semantic Relationships to Prioritise Indicators of Compromise in Additive Manufacturing Systems
arxiv_fulltext·2023-05-06
Leveraging Semantic Relationships to Prioritise Indicators of Compromise in Additive Manufacturing Systems
Leveraging Semantic Relationships to Prioritise Indicators of Compromise in Additive Manufacturing Systems
Mahender Kumar1
Gregory Epiphaniou2
Carsten Maple3
Kumar et al.
Cyber Security Research Group, WMG, University of Warwick
Coventry, United Kingdom
[email protected] [email protected] [email protected]
## Abstract
Additive manufacturing (AM) offers numerous benefits, such as manufacturing complex and customised designs quickly and cost-effectively, reducing material waste, and enabling on-demand production. However, several security challenges are associated with AM, making it increasingly attractive to attackers ranging from individual hackers to organised criminal gangs and nation-state actors. This paper addresses the cyber risk in AM to attackers by
Bugzilla
CVE-2019-3834 JON: struts1 reversion of fix for CVE-2014-0114
bugzilla·2019-02-15·CVSS 7.5
CVE-2019-3834 [HIGH] CVE-2019-3834 JON: struts1 reversion of fix for CVE-2014-0114
CVE-2019-3834 JON: struts1 reversion of fix for CVE-2014-0114
JON had resolved struts1 flaw CVE-2014-0114 with https://rhn.redhat.com/errata/RHSA-2014-0511.html, but reverted the fix in a later release.
Discussion:
Statement:
While the original flaw, CVE-2014-0114, was resolved as a precaution in JON 3.2.1, later further research revealed that JON did not expose the properties in an exploitable way, and was not vulnerable.
2019-05-17
Published