CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redhat5Debian Linux Enterprise Linux ServerEnterprise Linux Virtualization+2 moreNov 21, 2024 Oct 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote a...Show more |
3Canonical DebianHaxx3Curl Debian LinuxUbuntu LinuxNov 21, 2024 Oct 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service. |
4Canonical DebianJasper Project+1 more5Debian Linux JasperLinux Enterprise Desktop+2 moreNov 21, 2024 Oct 31, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c. |
2Debian Loofah Project2Debian Linux LoofahNov 21, 2024 Oct 30, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(),...Show more |
6Canonical DebianNetapp+3 more19Api Gateway Cloud BackupCn1610 Firmware+16 moreNov 21, 2024 Oct 30, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected...Show more |
6Canonical DebianNetapp+3 more22Api Gateway Application ServerCloud Backup+19 moreNov 21, 2024 Oct 29, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more |
2Debian Gnome2Debian Linux GthumbNov 21, 2024 Oct 29, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffe...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 29, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long t...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Oct 26, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attri...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 9, 2025 Oct 26, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239. |
4Canonical DebianOracle+1 more4Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxSystemd+1 moreJun 9, 2025 Oct 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to ro...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreAug 29, 2025 Oct 25, 2018 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via ph...Show more |
3Debian RedhatZmanda3Amanda Debian LinuxEnterprise LinuxNov 21, 2024 Oct 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allo...Show more |
3Debian GnuNetapp3Binutils Data OntapDebian LinuxNov 21, 2024 Oct 23, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when use...Show more |
3Debian GnuNetapp3Binutils Data OntapDebian LinuxNov 21, 2024 Oct 23, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_sectio...Show more |
3Debian GnuNetapp3Binutils Data OntapDebian LinuxNov 21, 2024 Oct 23, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_se...Show more |
3Debian RedhatSuse4Ansible Engine Ansible TowerDebian Linux+1 moreNov 21, 2024 Oct 23, 2018 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing...Show more |
6Canonical DebianKyzer+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Oct 23, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name). |
7Cabextract Project CanonicalDebian+4 more7Cabextract Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Oct 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. |