CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectRedhat4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Dec 3, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees |
3Linux OpensuseRedhat3Enterprise Linux LeapLinux KernelJun 17, 2026 Nov 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.4 MEDIUM· v2 In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large o...Show more |
5Canonical FedoraprojectLinux+2 more5Enterprise Linux FedoraLeap+2 moreJun 17, 2026 Nov 27, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and...Show more |
2Linux Redhat2Dhcp6c Enterprise LinuxNov 21, 2024 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. |
3Debian GnupgRedhat3Debian Linux Enterprise LinuxGnupgNov 21, 2024 Nov 27, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate. |
4Accountsservice Project DebianOpensuse+1 more4Accountsservice Debian LinuxEnterprise Linux+1 moreNov 21, 2024 Nov 27, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords. |
5Canonical OracleRedhat+2 more5Enterprise Linux Mysql WorkbenchSinec Infrastructure Network Services+2 moreJun 17, 2026 Nov 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c. |
3Ethz FedoraprojectRedhat3Enterprise Linux FedoraXquestNov 21, 2024 Nov 27, 2019 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 A password generation weakness exists in xquest through 2016-06-13. |
2Artifex Redhat93scale Api Management Enterprise LinuxEnterprise Linux Desktop+6 moreJun 17, 2026 Nov 27, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially cra...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrar...Show more |
3Debian Hardlink ProjectRedhat3Debian Linux Enterprise LinuxHardlinkNov 21, 2024 Nov 26, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. |
3Debian Hardlink ProjectRedhat3Debian Linux Enterprise LinuxHardlinkNov 21, 2024 Nov 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote att...Show more |
3Debian Hardlink ProjectRedhat3Debian Linux Enterprise LinuxHardlinkNov 21, 2024 Nov 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory...Show more |
4Debian FedoraprojectLibuser Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreJan 23, 2026 Nov 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 libuser has information disclosure when moving user's home directory |
3Fedoraproject Libuser ProjectRedhat3Enterprise Linux FedoraLibuserNov 21, 2024 Nov 25, 2019 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. |
3Debian QuaggaRedhat3Debian Linux Enterprise LinuxQuaggaNov 21, 2024 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal |
4Canonical Ibus ProjectOracle+1 more4Enterprise Linux IbusUbuntu Linux+1 moreJun 17, 2026 Nov 25, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attac...Show more |
3Linux NetappRedhat18Altavault Baseboard Management ControllerCodeready Linux Builder Eus+15 moreJun 17, 2026 Nov 25, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver. |
5Buildah Project Libpod ProjectOpensuse+2 more6Buildah Enterprise LinuxLeap+3 moreJun 17, 2026 Nov 25, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more |
2Python Redhat3Enterprise Linux Enterprise Virtualization HypervisorPyxmlNov 21, 2024 Nov 22, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 PyXML: Hash table collisions CPU usage Denial of Service |