CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOniguruma Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects...Show more |
2Debian Linux Ax252Ax25 Tools Debian LinuxNov 21, 2024 Nov 15, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with...Show more |
4Debian DrupalFedoraproject+1 more4Debian Linux DrupalEnterprise Linux+1 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields...Show more |
2Debian Gksu Polkit Project2Debian Linux Gksu PolkitNov 21, 2024 Nov 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session. |
5Avaya DebianMozilla+2 more27Aura Application Enablement Services Aura Application Server 5300Aura Communication Manager+24 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more |
3Chrony Project DebianFedoraproject3Chrony Debian LinuxFedoraNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Chrony before 1.29.1 has traffic amplification in cmdmon protocol |
3Clamav DebianFedoraproject3Clamav Debian LinuxFedoraNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ClamAV before 0.97.7: dbg_printhex possible information leak |
3Clamav DebianFedoraproject3Clamav Debian LinuxFedoraNov 21, 2024 Nov 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ClamAV before 0.97.7 has buffer overflow in the libclamav component |
3Clamav DebianFedoraproject3Clamav Debian LinuxFedoraNov 21, 2024 Nov 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ClamAV before 0.97.7 has WWPack corrupt heap memory |
2Debian Horms2Debian Linux PerditionNov 21, 2024 Nov 15, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections |
3Cyrus DebianFedoraproject3Debian Linux FedoraImapJun 17, 2026 Nov 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connec...Show more |
3Canonical DebianRack Cors Project3Debian Linux Rack CorsUbuntu LinuxJun 17, 2026 Nov 14, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in...Show more |
8Canonical DebianF5+5 more778Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+775 moreNov 21, 2024 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more |
3Debian IntelOpensuse59Debian Linux LeapXeon 3104 Firmware+56 moreJun 17, 2026 Nov 14, 2019 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access. |
9Canonical DebianFedoraproject+6 more160Apollo 2000 Firmware Apollo 4200 FirmwareCeleron 5305u Firmware+157 moreJun 17, 2026 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. |
4Debian FedoraprojectMoodle+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to |
2Debian Klibc Project2Debian Linux KlibcNov 21, 2024 Nov 14, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary co...Show more |
3Debian OpensuseXfce3Debian Linux OpensuseThunarNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error. |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more |