CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Smarty2Debian Linux SmartyNov 21, 2024 Nov 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGlibc+1 moreJun 17, 2026 Nov 19, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to re...Show more |
3Debian FedoraprojectLinuxfoundation3Debian Linux FedoraFoomatic FiltersNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 3.3 LOW· v2 foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduc...Show more |
2Debian Linuxfoundation2Debian Linux Foomatic FiltersNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 3.3 LOW· v2 foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct s...Show more |
2Cookie Signature Project Debian2Cookie Signature Debian LinuxNov 21, 2024 Nov 19, 2019 N/A· v4 4.4 MEDIUM· v3 3.5 LOW· v2 Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used. |
2Debian Nusoap Project2Debian Linux NusoapNov 21, 2024 Nov 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. |
2Debian Sniffit Project2Debian Linux SniffitNov 21, 2024 Nov 19, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout random...Show more |
uzbl: Information disclosure via world-readable cookies storage file |
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) |
2Debian Suckless2Debian Linux SurfNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 surf: cookie jar has read access from other local user |
4Apache DebianFasterxml+1 more5Debian Linux Jackson Mapper AslJboss Enterprise Application Platform+2 moreJun 17, 2026 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by tr...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() f...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures,...Show more |
7Broadcom CanonicalDebian+4 more18Active Iq Unified Manager Aff Baseboard Management ControllerBrocade Fabric Operating System Firmware+15 moreJun 17, 2026 Nov 18, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by trigger...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by trigge...Show more |
7Broadcom CanonicalDebian+4 more18Active Iq Unified Manager Aff Baseboard Management ControllerBrocade Fabric Operating System Firmware+15 moreJun 17, 2026 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, ak...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Nov 18, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc...Show more |
4Debian FedoraprojectOniguruma Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects...Show more |