CVEs (779)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Canonical DebianFedoraproject+4 more18Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+15 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. |
8Canonical DebianFedoraproject+5 more22Active Iq Performance Analytics Services Debian LinuxEnterprise Linux+19 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An un...Show more |
4Fedoraproject OpensuseOpenwsman Project+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreNov 21, 2024 Mar 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this...Show more |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise LinuxEnterprise Linux Desktop+13 moreNov 21, 2024 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, e...Show more |
5Debian OpensuseOracle+2 more9Backports Sle Communications Operations MonitorDebian Linux+6 moreNov 21, 2024 Feb 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. |
5Canonical DebianF5+2 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Feb 15, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. |
5Canonical DebianElfutils Project+2 more11Debian Linux ElfutilsEnterprise Linux+8 moreNov 21, 2024 Feb 9, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash...Show more |
2Elfutils Project Redhat8Elfutils Enterprise LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Feb 9, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program...Show more |
5Debian OpensuseOracle+2 more9Backports Sle Communications Operations MonitorDebian Linux+6 moreNov 21, 2024 Feb 6, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreNov 21, 2024 Feb 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the p...Show more |
5Canonical DebianFedoraproject+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Feb 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have un...Show more |
10Apache CanonicalDebian+7 more19Debian Linux Enterprise LinuxEnterprise Linux Eus+16 moreDec 18, 2025 Jan 31, 2019 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validati...Show more |
9Canonical DebianFedoraproject+6 more20Debian Linux Element SoftwareEnterprise Linux+17 moreMay 28, 2026 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g.,...Show more |
5Canonical DebianElfutils Project+2 more11Debian Linux ElfutilsEnterprise Linux+8 moreNov 21, 2024 Jan 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core fi...Show more |
3Netapp OracleRedhat10Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+7 moreNov 21, 2024 Jan 16, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker...Show more |
6Canonical DebianMariadb+3 more12Debian Linux Enterprise LinuxEnterprise Linux Eus+9 moreNov 21, 2024 Jan 16, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability...Show more |
3Netapp OracleRedhat10Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+7 moreNov 21, 2024 Jan 16, 2019 N/A· v4 5.0 MEDIUM· v3 1.2 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker...Show more |
3Netapp OracleRedhat10Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+7 moreNov 21, 2024 Jan 16, 2019 N/A· v4 4.1 MEDIUM· v3 1.9 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker w...Show more |
4Canonical NetappOracle+1 more11Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+8 moreNov 21, 2024 Jan 16, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulner...Show more |
3Netapp OracleRedhat10Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+7 moreNov 21, 2024 Jan 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows low privilege...Show more |