CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 22, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files |
1Redhat 2Enterprise Linux Redhat Upgrade ToolNov 21, 2024 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
3Debian FedoraprojectRedhat7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Nov 20, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |
2Openpegasus Redhat2Enterprise Linux Tog PegasusNov 21, 2024 Nov 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 tog-Pegasus has a package hash collision DoS vulnerability |
3Fedoraproject RedhatTrusted Boot Project3Enterprise Linux FedoraTrusted BootNov 21, 2024 Nov 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability |
3Linux OpensuseRedhat3Enterprise Linux LeapLinux KernelJun 17, 2026 Nov 18, 2019 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the Linux kernel before 5.3.4 allows attackers to cause a denial of service (memory consumption), aka CID...Show more |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxJun 17, 2026 Nov 18, 2019 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux kernel before 5.3.6 allows attackers to cause a denial of service (memory consumption), aka CID-78bee...Show more |
4Canonical FedoraprojectLinux+1 more4Enterprise Linux FedoraLinux Kernel+1 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by tr...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() f...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures,...Show more |
4Debian FedoraprojectOniguruma Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects...Show more |
4Debian DrupalFedoraproject+1 more4Debian Linux DrupalEnterprise Linux+1 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields...Show more |
5Avaya DebianMozilla+2 more27Aura Application Enablement Services Aura Application Server 5300Aura Communication Manager+24 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more |
9Canonical DebianFedoraproject+6 more160Apollo 2000 Firmware Apollo 4200 FirmwareCeleron 5305u Firmware+157 moreJun 17, 2026 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 14, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle before 2.2.2 has users' private files included in course backups |
4Debian FedoraprojectMoodle+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to |