CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFreedesktop+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 Jan 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in...Show more |
4Canonical DebianLinux+1 more5Debian Linux Enterprise LinuxEnterprise Mrg+2 moreNov 21, 2024 Dec 18, 2018 N/A· v4 8.0 HIGH· v3 6.7 MEDIUM· v2 A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerabilit...Show more |
5Canonical DebianNetapp+2 more8Debian Linux E Series Santricity Os ControllerEnterprise Linux+5 moreNov 21, 2024 Dec 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
6Apple CanonicalDebian+3 more9Debian Linux E Series Santricity Os ControllerEnterprise Linux+6 moreNov 21, 2024 Dec 7, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. |
8Apple CanonicalDebian+5 more18Debian Linux E Series Santricity Os ControllerEnterprise Linux+15 moreNov 21, 2024 Dec 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
5Canonical DebianNetapp+2 more8Debian Linux E Series Santricity Os ControllerEnterprise Linux+5 moreNov 21, 2024 Dec 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
2Nodejs Redhat8Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreDec 27, 2024 Nov 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and...Show more |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreNov 21, 2024 Nov 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cle...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreNov 21, 2024 Nov 16, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats. |
4Canonical DebianRedhat+1 more5Debian Linux Enterprise LinuxOpenssl+2 moreNov 21, 2024 Nov 16, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the o...Show more |
3Canonical PostgresqlRedhat3Enterprise Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL stat...Show more |
2Nasm Redhat2Enterprise Linux Netwide AssemblerNov 21, 2024 Nov 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters. |
2Nasm Redhat2Enterprise Linux Netwide AssemblerNov 21, 2024 Nov 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input. |
3Libwpd Project RedhatSuse3Enterprise Linux LibwpdSuse Linux Enterprise ServerNov 21, 2024 Nov 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h. |
1Redhat 2Enterprise Linux RichfacesNov 3, 2025 Nov 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain o...Show more |
4Canonical DebianFreedesktop+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 Nov 2, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo. |
3Debian GlusterRedhat3Debian Linux Enterprise LinuxGlusterfsNov 21, 2024 Oct 31, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, cr...Show more |
3Canonical GnuRedhat3Enterprise Linux GettextUbuntu LinuxNov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. |
2Redhat Zmanda2Amanda Enterprise LinuxNov 21, 2024 Oct 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to b...Show more |
3Debian RedhatZmanda3Amanda Debian LinuxEnterprise LinuxNov 21, 2024 Oct 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allo...Show more |