CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. |
2Debian Xcfa Project2Debian Linux XcfaNov 21, 2024 Nov 21, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254. |
3Debian FedoraprojectOniguruma Project3Debian Linux FedoraOnigurumaJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-...Show more |
2Debian Redmine2Debian Linux RedmineJun 17, 2026 Nov 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query. |
2Debian Xcftools Project2Debian Linux XcftoolsJun 17, 2026 Nov 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size,...Show more |
2Debian Xcftools Project2Debian Linux XcftoolsJun 17, 2026 Nov 21, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.0.7. An integer overflow can occur while walking through tiles that cou...Show more |
2Debian Rc Project2Debian Linux RcNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 rc before 1.7.1-5 insecurely creates temporary files. |
29base Project Debian29base Debian LinuxNov 21, 2024 Nov 21, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames. |
2Debian Net Ldap Project2Debian Linux Net LdapNov 21, 2024 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords. |
3Canonical DebianMono Project3Debian Linux MonoUbuntu LinuxNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mono 2.10.x ASP.NET Web Form Hash collision DoS |
2Debian Pam Shield Project2Debian Linux Pam ShieldNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 pam_shield before 0.9.4: Default configuration does not perform protective action |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values...Show more |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for a...Show more |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain...Show more |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
2Debian Gnupg2Debian Linux GnupgNov 21, 2024 Nov 20, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file. |
3Canonical DebianPostgresql3Debian Linux Postgresql CommonUbuntu LinuxJun 17, 2026 Nov 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation. |
2Debian Weborf Project2Debian Linux WeborfNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP. |
3Debian FedoraprojectRedhat7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Nov 20, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |