CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectRedhat4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Dec 3, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees |
2Debian Stanford2Debian Linux WebauthNov 21, 2024 Dec 3, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 webauth before 4.6.1 has authentication credential disclosure |
2Debian Freebsd2Debian Linux FreebsdNov 21, 2024 Dec 2, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 FreeBSD: Input Validation Flaw allows local users to gain elevated privileges |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpenslp+1 moreNov 21, 2024 Dec 2, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 openslp: SLPIntersectStringList()' Function has a DoS vulnerability |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Dec 1, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraRabbitmq C+1 moreJun 17, 2026 Dec 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could re...Show more |
3Debian FedoraprojectProftpd3Debian Linux FedoraProftpdJun 17, 2026 Nov 30, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL inst...Show more |
5Canonical DebianLinux+2 more9Active Iq Unified Manager Debian LinuxHci Compute Node+6 moreJun 17, 2026 Nov 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result. |
2Debian Gnupg3Debian Linux GnupgLibgcryptNov 21, 2024 Nov 29, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation,...Show more |
2Debian Gnupg3Debian Linux GnupgLibgcryptNov 21, 2024 Nov 29, 2019 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using cr...Show more |
3Debian PuppetRuby Lang5Debian Linux Puppet AgentPuppet Enterprise+2 moreNov 21, 2024 Nov 29, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers vi...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Nov 29, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of se...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Nov 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Nov 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+11 moreJun 17, 2026 Nov 28, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already f...Show more |
2Debian Vsftpd Project2Debian Linux VsftpdNov 21, 2024 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp. |
3Debian Packagekit ProjectRedhat3Debian Linux Enterprise Linux ServerPackagekitNov 21, 2024 Nov 27, 2019 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code. |
3Debian OpensuseOtrs5Debian Linux FaqOpensuse+2 moreNov 21, 2024 Nov 27, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not ver...Show more |
3Debian GnupgRedhat3Debian Linux Enterprise LinuxGnupgNov 21, 2024 Nov 27, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate. |
4Accountsservice Project DebianOpensuse+1 more4Accountsservice Debian LinuxEnterprise Linux+1 moreNov 21, 2024 Nov 27, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords. |