CVE-2019-5460
https://notcve.org/view.php?id=CVE-2019-5460
Double Free in VLC versions <= 3.0.6 leads to a crash. Una vulnerabilidad de Doble Liberación en VLC versiones anteriores a 3.0.6 (incluida), conlleva a un bloqueo. • http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html https://hackerone.com/reports/503208 • CWE-415: Double Free •
CVE-2019-5459
https://notcve.org/view.php?id=CVE-2019-5459
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. Un desbordamiento de enteros de VLC Media Player versiones anteriores a 3.0.7, conlleva a una lectura fuera de banda. • http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00005.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00037.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00040.html http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00081.html https://hackerone.com/reports/502816 • CWE-191: Integer Underflow (Wrap or Wraparound) •
CVE-2019-14383
https://notcve.org/view.php?id=CVE-2019-14383
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. J2B en libopenmpt anterior a versión 0.4.2, permite un error de aserción durante el análisis de archivos con los STL de depuración. • http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00084.html http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00085.html https://lib.openmpt.org/libopenmpt/2019/01/22/security-updates-0.4.2-0.3.15-0.2.11253-beta37-0.2.7561-beta20.5-p13-0.2.7386-beta20.3-p16 • CWE-617: Reachable Assertion •
CVE-2018-20860
https://notcve.org/view.php?id=CVE-2018-20860
libopenmpt before 0.3.13 allows a crash with malformed MED files. libopenmpt anterior a versión 0.3.13, permite un bloqueo con archivos MED malformados. • http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00084.html http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00085.html https://lib.openmpt.org/libopenmpt/2018/10/21/security-updates-0.3.13-0.2.10933-beta36-0.2.7561-beta20.5-p11-0.2.7386-beta20.3-p14 • CWE-20: Improper Input Validation •
CVE-2019-14271
https://notcve.org/view.php?id=CVE-2019-14271
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container. En Docker versión 19.03.x anterior a 19.03.1, vinculado contra la Biblioteca C de GNU (también se conoce como glibc), la inyección de código puede ocurrir cuando la facilidad nsswitch carga dinámicamente una biblioteca dentro de un chroot que alberga el contenido del contenedor. • http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html https://docs.docker.com/engine/release-notes https://github.com/moby/moby/issues/39449 https://seclists.org/bugtraq/2019/Sep/21 https://security.netapp.com/advisory/ntap-20190828-0003 https://www.debian.org/security/2019/dsa-4521 • CWE-665: Improper Initialization •