CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. When running Git in the Windows Subsystem for Linux (also known as "WSL") while acce...Show more |
An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks option of git fast-import is exposed also via the in-stream comma...Show more |
2Microsoft Opensuse3Leap Visual Studio 2017Visual Studio 2019Nov 21, 2024 Jan 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A tampering vulnerability exists when Git for Visual Studio improperly handles virtual drive paths, aka 'Git for Visual Studio Tampering Vulnerability'. |
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version...Show more |
2Opensuse Suse3Backports Sle InnLeapNov 21, 2024 Jan 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user inn to root via symlink attacks. This issue affects: SUSE Linux Enterprise Server 11 inn v...Show more |
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects:...Show more |
6Debian FedoraprojectNetapp+3 more24Cloud Backup Clustered Data OntapCommunications Cloud Native Core Network Function Cloud Native Environment+21 moreDec 17, 2025 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. |
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreNov 21, 2024 Jan 21, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeB...Show more |
3Apt Cacher Ng Project DebianOpensuse4Apt Cacher Ng BackportsDebian Linux+1 moreNov 21, 2024 Jan 21, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port...Show more |
4Canonical OpensuseSamba+1 more7Directory Server Diskstation ManagerLeap+4 moreJan 14, 2025 Jan 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local va...Show more |
2Opensuse Squid Analysis Report Generator Project3Backports Sle LeapSquid Analysis Report GeneratorNov 21, 2024 Jan 21, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temporary directory /tmp/sarg. As the root user, sarg creates this directory or reuses an exis...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSamba+1 moreNov 21, 2024 Jan 21, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not au...Show more |
5Canonical FedoraprojectNetapp+2 more7Active Iq Unified Manager Cloud BackupFedora+4 moreJun 9, 2025 Jan 21, 2020 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSalt+1 moreNov 21, 2024 Jan 17, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrar...Show more |
4Debian Libslirp ProjectOpensuse+1 more4Debian Linux LeapLibslirp+1 moreNov 21, 2024 Jan 16, 2020 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead...Show more |
5Cacti DebianFedoraproject+2 more7Backports Sle CactiDebian Linux+4 moreNov 21, 2024 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more |
4Fedoraproject OpensuseOracle+1 more5Fedora LeapSolaris+2 moreNov 21, 2024 Jan 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors. |
6Canonical DebianNetapp+3 more23Active Iq Unified Manager Debian LinuxE Series Performance Analyzer+20 moreNov 21, 2024 Jan 15, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerabi...Show more |
7Canonical DebianMcafee+4 more23Active Iq Unified Manager Debian LinuxE Series Performance Analyzer+20 moreNov 21, 2024 Jan 15, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated...Show more |
7Canonical DebianMcafee+4 more27Active Iq Unified Manager Commerce Experience ManagerCommerce Guided Search+24 moreNov 21, 2024 Jan 15, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult t...Show more |