CVEs (1,454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local...Show more |
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon se...Show more |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxOpensuse+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. |
5Debian FedoraprojectOpensuse+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
3Dovecot OpensuseRedhat4Dovecot Enterprise LinuxLeap+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. |
3Debian HordeOpensuse3Debian Linux GroupwareOpensuseNov 21, 2024 Nov 5, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions |
5Canonical DebianIcoutils Project+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafte...Show more |
5Canonical DebianIcoutils Project+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a...Show more |
4Canonical DebianIcoutils Project+1 more5Debian Linux IcoutilsLeap+2 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable. |
4Debian GnomeOpensuse+1 more4Debian Linux Enterprise LinuxEvince+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 evince is missing a check on number of pages which can lead to a segmentation fault |
2Mdadm Project Opensuse2Mdadm OpensuseNov 21, 2024 Jun 8, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root. |
2Opensuse Uclouvain2Openjpeg OpensuseNov 21, 2024 Apr 10, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file...Show more |
4Debian LibtiffOpensuse+1 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Mar 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craft...Show more |
5Debian FedoraprojectOpensuse+2 more6Debian Linux FedoraLeap+3 moreMay 13, 2026 Dec 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. |
4Opensuse Opensuse ProjectPython+1 more4Opensuse OpensusePython+1 moreMay 13, 2026 Aug 24, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the...Show more |
2Encfs Project Opensuse3Encfs LeapOpensuseMay 13, 2026 Aug 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes". |
4Fedoraproject Jasper ProjectOpensuse+1 more5Fedora JasperLeap+2 moreMay 13, 2026 Aug 2, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file. |
4Fedoraproject Jasper ProjectOpensuse+1 more5Fedora JasperLeap+2 moreMay 13, 2026 Jul 25, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000...Show more |
7Canonical DebianFedoraproject+4 more20Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+17 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more |