CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Cabextract Project CanonicalDebian+4 more7Cabextract Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Oct 23, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. |
2Qemu Redhat3Enterprise Linux OpenstackQemuNov 21, 2024 Oct 19, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value. |
4Canonical DebianMozilla+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Oct 18, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9. |
4Canonical DebianMozilla+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Oct 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. |
4Canonical DebianMozilla+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Oct 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. |
6Canonical DebianLibssh+3 more9Debian Linux Enterprise LinuxLibssh+6 moreNov 21, 2024 Oct 17, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access. |
4Canonical DebianGit Scm+1 more11Ansible Tower Debian LinuxEnterprise Linux+8 moreNov 21, 2024 Oct 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproj...Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxNov 21, 2024 Sep 28, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of servi...Show more |
5Apache CanonicalNetapp+2 more9Enterprise Linux Enterprise Manager Ops CenterHospitality Guest Access+6 moreNov 21, 2024 Sep 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2...Show more |
3Canonical HaproxyRedhat5Enterprise Linux HaproxyOpenshift+2 moreNov 21, 2024 Sep 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service. |
4Canonical DebianOpenssl+1 more4Debian Linux Enterprise LinuxOpenssl+1 moreNov 21, 2024 Sep 10, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys. |
4Canonical DebianHaxx+1 more4Debian Linux Enterprise LinuxLibcurl+1 moreNov 21, 2024 Sep 5, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large tem...Show more |
4Artifex CanonicalDebian+1 more8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Sep 5, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter. |
4Artifex CanonicalDebian+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Sep 5, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified...Show more |
4Debian GlusterOpensuse+1 more7Debian Linux Enterprise LinuxEnterprise Linux Server+4 moreNov 21, 2024 Sep 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume. |
4Debian GlusterOpensuse+1 more7Debian Linux Enterprise LinuxEnterprise Linux Server+4 moreNov 21, 2024 Sep 4, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create a...Show more |
4Debian GlusterOpensuse+1 more6Debian Linux Enterprise LinuxEnterprise Linux Server+3 moreNov 21, 2024 Sep 4, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a...Show more |
4Canonical DebianLibtirpc Project+1 more8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Aug 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maxim...Show more |
2Postgresql Redhat2Enterprise Linux Postgresql Jdbc DriverNov 21, 2024 Aug 30, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition...Show more |
4Apache CanonicalDebian+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Aug 26, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code fo...Show more |