CVE-2019-0116
published 2019-05-17CVE-2019-0116: An out of bound read in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow…
PriorityP412medium4.4CVSS 3.0
AVLACLPRHUINSUCNINAH
EPSS
0.34%
26.4th percentile
An out of bound read in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow a privileged user to potentially enable denial of service via local access.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
| intel | graphics_driver | — | — |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7fpp-w42q-q492: An out of bound read in KMD module for Intel(R) Graphics Driver before version 10
ghsa_unreviewed·2022-05-24
CVE-2019-0116 [MEDIUM] CWE-125 GHSA-7fpp-w42q-q492: An out of bound read in KMD module for Intel(R) Graphics Driver before version 10
An out of bound read in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow a privileged user to potentially enable denial of service via local access.
Red Hat
struts2: Struts internals manipulation via cookie request headers
vendor_redhat·2014-05-05·CVSS 7.5
CVE-2014-0116 [HIGH] struts2: Struts internals manipulation via cookie request headers
struts2: Struts internals manipulation via cookie request headers
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included
No detection rules found.
No public exploits indexed.
2019-05-17
Published