CVE-2019-1284
published 2019-09-11CVE-2019-1284: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.93%
56.6th percentile
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| djangoproject | django | >= 3.2a1 < 3.2.22 | 3.2.22 |
| djangoproject | django | >= 4.1a1 < 4.1.12 | 4.1.12 |
| djangoproject | django | >= 4.2a1 < 4.2.6 | 4.2.6 |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2008 | — | — |
| msrc | windows_7_for_32-bit_systems_service_pack_1 | — | — |
| msrc | windows_7_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_itanium-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_itanium-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
ghsa7.5HIGH
vendor_msrc7.8HIGH
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Pidgin: Pidgin: Denial of Service via excessively long username
vendor_redhat·2026-03-21·CVSS 6.9
CVE-2019-25544 [MEDIUM] CWE-1284 Pidgin: Pidgin: Denial of Service via excessively long username
Pidgin: Pidgin: Denial of Service via excessively long username
Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.
A flaw was found in Pidgin. Local attackers can exploit this denial of service vulnerability by providing an excessively long username string during account creation. This can cause the application to crash when joining a chat, leading to the application becoming unavailable.
Statement: This Moderate impact denial of service flaw in Pidgin allows a local attacker to crash the application.
Red Hat
libarchive: heap-based buffer overflow in archive_read_support_format_lha.c due to insufficient validation of UTF-16 input
vendor_redhat·2019-11-26·CVSS 6.5
CVE-2019-20509 [MEDIUM] CWE-125 libarchive: heap-based buffer overflow in archive_read_support_format_lha.c due to insufficient validation of UTF-16 input
libarchive: heap-based buffer overflow in archive_read_support_format_lha.c due to insufficient validation of UTF-16 input
[REJECTED CVE] A vulnerability has been identified in Libarchive in archive_read_support_format_lha.c file. It does not ensure valid sizes for UTF-16 input, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted LHA archive.
Statement: This CVE has been rejected by Upstream, because the vulnerability was introduced and fixed in the same version, so there is actually no released version with the vulnerable code: https://github.com/libarchive/libarchive/issues/1284#issuecomment-598381071
Package: libarchive (Red Hat Enterprise Linux 6) - Not affected
Package: libarchive (Red Hat Enterprise Linux 7)
Microsoft
DirectX Elevation of Privilege Vulnerability
vendor_msrc·2019-09-10·CVSS 7.8
CVE-2019-1284 [HIGH] DirectX Elevation of Privilege Vulnerability
DirectX Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses the vulnerability by correcting how DirectX handles objects in memory.
Microsoft Graphics Component: Microsoft Graphics Component
Microsoft: Microsoft
Customer Action Required: Yes
GHSA
Django Denial-of-service in django.utils.text.Truncator
ghsa·2023-11-03·CVSS 7.5
CVE-2023-43665 [HIGH] CWE-1284 Django Denial-of-service in django.utils.text.Truncator
Django Denial-of-service in django.utils.text.Truncator
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML text. The chars() and words() methods are used to implement the truncatechars_html and truncatewords_html template filters, which are thus also vulnerable. NOTE: this issue exists because of an incomplete fix for CVE-2019-14232.
GHSA
GHSA-jmjc-rh8r-gw8j: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2019-1284 [HIGH] GHSA-jmjc-rh8r-gw8j: An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'
An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'.
No detection rules found.
No public exploits indexed.
2019-09-11
Published