CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Nov 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes a...Show more |
With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a ser...Show more |
2Fedoraproject Proftpd2Fedora ProftpdJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOniguruma+2 moreJun 17, 2026 Nov 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c. |
4Fedoraproject GoogleOpensuse+1 more6Backports ChromeEnterprise Linux Desktop+3 moreJun 17, 2026 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectLibuser Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreJan 23, 2026 Nov 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 libuser has information disclosure when moving user's home directory |
3Fedoraproject Libuser ProjectRedhat3Enterprise Linux FedoraLibuserNov 21, 2024 Nov 25, 2019 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. |
2Fedoraproject Gksu Polkit Project2Fedora Gksu PolkitNov 21, 2024 Nov 25, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation |
2Fedoraproject Gnome2Fedora Gnome System LogNov 21, 2024 Nov 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gnome-system-log polkit policy allows arbitrary files on the system to be read |
3Fedoraproject KubernetesRedhat3Cri O FedoraOpenshift Container PlatformJun 17, 2026 Nov 25, 2019 N/A· v4 5.0 MEDIUM· v3 6.0 MEDIUM· v2 A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of...Show more |
5Broadcom DebianFedoraproject+2 more5Debian Linux FedoraOpenstack+2 moreJun 17, 2026 Nov 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more |
3Fedoraproject OpensusePhpmyadmin4Backports Sle FedoraLeap+1 moreJun 17, 2026 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 22, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation sho...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. |
3Debian FedoraprojectOniguruma Project3Debian Linux FedoraOnigurumaJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-...Show more |
2Fedoraproject Oniguruma Project2Fedora OnigurumaJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to...Show more |
2Fedoraproject Ikiwiki2Fedora IkiwikiNov 21, 2024 Nov 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify actio...Show more |