CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 10, 2019 N/A· v4 5.4 MEDIUM· v3 6.4 MEDIUM· v2 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out o...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 10, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba,...Show more |
7Canonical DebianFedoraproject+4 more9Debian Linux Enterprise Manager Ops CenterFedora+6 moreNov 21, 2024 Dec 6, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and...Show more |
The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (please also check the additional hardenings after this fix). This allowed local attackers with control...Show more |
4Debian OpensuseOracle+1 more5Debian Linux LeapSolaris+2 moreNov 21, 2024 Dec 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/asn1/cms/packet-cms-template.c by ensuring that an object identifier is set to NULL after a ContentInf...Show more |
3Aquamaniac DebianOpensuse3Debian Linux GwenhywfarLeapNov 21, 2024 Dec 3, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. |
2Opensuse Shadowsocks3Backports Sle LeapShadowsocks LibevNov 21, 2024 Dec 3, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code executi...Show more |
2Opensuse Shadowsocks3Backports LeapShadowsocks LibevNov 21, 2024 Dec 3, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path...Show more |
2Apache Opensuse3Leap Mod FcgidOpensuseNov 21, 2024 Dec 3, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07. |
3Freeradius OpensuseRedhat3Enterprise Linux FreeradiusLeapNov 21, 2024 Dec 3, 2019 N/A· v4 6.5 MEDIUM· v3 2.9 LOW· v2 In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an atta...Show more |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_pro.c driver, aka CID-ead16e53c2f0. |
4Debian LinuxOpensuse+1 more4Debian Linux LeapLinux Kernel+1 moreNov 21, 2024 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_fd.c driver, aka CID-30a8beeb3042. |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Dec 3, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca. |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/class/cdc-acm.c driver, aka CID-c52873e5a1ef. |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Dec 3, 2019 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 In the Linux kernel before 5.2.10, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver, aka CID-9c09b214f30e. |
3Canonical LinuxOpensuse3Leap Linux KernelUbuntu LinuxNov 21, 2024 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 5.3.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/nfc/pn533/usb.c driver, aka CID-6af3aa57a098. |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 5.3.6, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/ieee802154/atusb.c driver, aka CID-7fd25e6fc035. |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelNov 21, 2024 Dec 3, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79. |
5Canonical DebianLinux+2 more9Active Iq Unified Manager Debian LinuxHci Compute Node+6 moreNov 21, 2024 Nov 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result. |