CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Nov 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code exec...Show more |
4Debian FedoraprojectPhpmailer Project+1 more4Debian Linux FedoraPhpmailer+1 moreNov 21, 2024 Nov 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. |
3Canonical DigitalcorporaFedoraproject3Fedora TcpflowUbuntu LinuxNov 21, 2024 Oct 17, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histo...Show more |
2Broadcom Fedoraproject2Fedora TcpreplayNov 21, 2024 Oct 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact. |
2Broadcom Fedoraproject2Fedora TcpreplayNov 21, 2024 Oct 17, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4() in incremental_check...Show more |
3Apache FedoraprojectOracle3Fedora PdfboxRetail Xstore Point Of ServiceNov 21, 2024 Oct 5, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree. |
2Fedoraproject Golang2Fedora NetNov 21, 2024 Oct 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHe...Show more |
2Fedoraproject Golang2Fedora NetNov 21, 2024 Oct 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parse...Show more |
2Fedoraproject Golang2Fedora NetNov 21, 2024 Oct 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not compl...Show more |
2Adplug Project Fedoraproject2Adplug FedoraNov 21, 2024 Oct 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Sep 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause...Show more |
2Fedoraproject Golang2Fedora NetNov 21, 2024 Sep 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call. |
2Fedoraproject Golang2Fedora NetNov 21, 2024 Sep 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call. |
2Fedoraproject Golang2Fedora NetNov 21, 2024 Sep 16, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. Thi...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibx11+1 moreNov 21, 2024 Aug 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on,...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.6 MEDIUM· v3 1.9 LOW· v2 A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Luc...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via stat...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via stati...Show more |
3Debian FedoraprojectLibcgroup Project3Debian Linux FedoraLibcgroupNov 21, 2024 Aug 14, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information. |