Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2019-04-23 CVE-2019-2708 Unspecified vulnerability in Oracle Berkeley DB
Vulnerability in the Data Store component of Oracle Berkeley DB.
local
low complexity
oracle
3.3
2019-04-23 CVE-2019-2605 Unspecified vulnerability in Oracle Business Intelligence 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Web Catalog).
network
high complexity
oracle
3.4
2019-04-23 CVE-2019-2577 Unspecified vulnerability in Oracle Solaris 11
Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: File Locking Services).
local
low complexity
oracle
3.3
2019-04-17 CVE-2019-0162 Unspecified vulnerability in Intel -
Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel
3.8
2019-04-17 CVE-2019-9219 Authorization Bypass Through User-Controlled Key vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
network
high complexity
gitlab CWE-639
3.7
2019-04-17 CVE-2019-9179 Information Exposure vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
network
high complexity
gitlab CWE-200
3.7
2019-04-17 CVE-2019-9171 Missing Authorization vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1.
network
high complexity
gitlab CWE-862
3.7
2019-04-17 CVE-2019-9495 Information Exposure Through Discrepancy vulnerability in multiple products
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns.
3.7
2019-04-12 CVE-2019-11191 Race Condition vulnerability in Linux Kernel
The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat.
local
high complexity
linux CWE-362
2.5
2019-04-10 CVE-2019-6156 Improper Locking vulnerability in Lenovo products
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash.
local
low complexity
lenovo CWE-667
3.3