CVEs (1,891)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. |
4Fedoraproject OpenslpRedhat+1 more16Enterprise Linux Desktop Enterprise Linux For Ibm Z SystemsEnterprise Linux For Ibm Z Systems Eus+13 moreOct 30, 2025 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. |
3Debian Packagekit ProjectRedhat3Debian Linux Enterprise Linux ServerPackagekitNov 21, 2024 Nov 27, 2019 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code. |
2Artifex Redhat93scale Api Management Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 Nov 27, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially cra...Show more |
4Fedoraproject GoogleOpensuse+1 more6Backports ChromeEnterprise Linux Desktop+3 moreNov 21, 2024 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectRedhat7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Nov 20, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |
8Canonical DebianF5+5 more778Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+775 moreNov 21, 2024 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more |
9Canonical DebianFedoraproject+6 more160Apollo 2000 Firmware Apollo 4200 FirmwareCeleron 5305u Firmware+157 moreMay 28, 2026 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. |
3Isc OpensuseRedhat19Dhcpd Enterprise LinuxEnterprise Linux Desktop+16 moreApr 11, 2025 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but t...Show more |
6Canonical DebianFedoraproject+3 more23Debian Linux Enterprise LinuxEnterprise Linux Desktop+20 moreNov 3, 2025 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI pro...Show more |
6Arista DebianFedoraproject+3 more11Cloudvision Portal Debian LinuxDeveloper Tools+8 moreNov 21, 2024 Oct 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that veri...Show more |
2Eclipse Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+4 moreNov 21, 2024 Oct 17, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks. |
7Canonical DebianFedoraproject+4 more15Debian Linux Element Software Management NodeEnterprise Linux+12 moreNov 21, 2024 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreNov 21, 2024 Oct 16, 2019 N/A· v4 4.7 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attack...Show more |
3Netapp OracleRedhat14E Series Santricity Os Controller E Series Santricity Storage ManagerE Series Santricity Unified Manager+11 moreNov 21, 2024 Oct 16, 2019 N/A· v4 4.2 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u221; Java SE Embedded: 8u221. Difficult to exploit vulnerability allo...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreNov 21, 2024 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulne...Show more |
3Netapp OracleRedhat12E Series Santricity Os Controller E Series Santricity Storage ManagerE Series Santricity Unified Manager+9 moreNov 21, 2024 Oct 16, 2019 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to explo...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreNov 21, 2024 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulne...Show more |
4Debian NetappOracle+1 more12Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+9 moreNov 21, 2024 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network acc...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreNov 21, 2024 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to ex...Show more |