CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat3Enterprise Linux FedoraPagureNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Pagure: XSS possible in file attachment endpoint |
2Fedoraproject Oracle2Fedora Mysql Gui ToolsNov 21, 2024 Nov 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console |
3Fedoraproject OpensuseSamba3Fedora LeapSambaJun 17, 2026 Nov 6, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issu...Show more |
3Fedoraproject OpensuseSamba3Fedora LeapSambaJun 17, 2026 Nov 6, 2019 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory D...Show more |
2Fedoraproject Samba2Fedora SambaJun 17, 2026 Nov 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files...Show more |
5Debian FedoraprojectPypa+2 more6Debian Linux FedoraOpenshift+3 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
4Fedoraproject OpensusePhp Gettext Project+1 more4Enterprise Linux FedoraLeap+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. |
3Fedoraproject RedhatReviewboard4Djblets Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. |
3Debian FedoraprojectSmokeping3Debian Linux FedoraSmokepingNov 21, 2024 Nov 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. |
3Fedoraproject RedhatSensiolabs3Enterprise Linux FedoraSymfonyNov 21, 2024 Nov 1, 2019 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 php-symfony2-Validator has loss of information during serialization |
2Fedoraproject Mantisbt2Fedora MantisbtNov 21, 2024 Oct 31, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version. |
2Fedoraproject Mantisbt2Fedora MantisbtNov 21, 2024 Oct 31, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 6.8 MEDIUM· v3 6.9 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() a...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exc...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV t...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like...Show more |
2Fedoraproject Systemd Project2Fedora SystemdNov 21, 2024 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: Thi...Show more |