CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxOpensuse+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. |
3Consolekit Project DebianRedhat3Consolekit Debian LinuxEnterprise LinuxNov 21, 2024 Nov 13, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session. |
5Debian FedoraprojectOpensuse+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
3Debian PhpRedhat3Debian Linux Enterprise LinuxPhpNov 21, 2024 Nov 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output. |
3Debian GnomeRedhat3Debian Linux Enterprise LinuxGdk PixbufNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxJun 17, 2026 Nov 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Nov 7, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_para...Show more |
5Broadcom LinuxNetapp+2 more17Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+14 moreJun 17, 2026 Nov 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraPagureNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Pagure: XSS possible in file attachment endpoint |
1Redhat 2Enterprise Linux Enterprise MrgNov 21, 2024 Nov 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace. |
3Dovecot OpensuseRedhat4Dovecot Enterprise LinuxLeap+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. |
4Isc NicNlnetlabs+1 more4Bind Enterprise LinuxKnot Resolver+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Cache Poisoning issue exists in DNS Response Rate Limiting. |
4Debian GnomeOpensuse+1 more4Debian Linux Enterprise LinuxGnome Display Manager+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 2.4 LOW· v3 2.1 LOW· v2 gdm3 3.14.2 and possibly later has an information leak before screen lock |
5Canonical DebianIcoutils Project+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafte...Show more |
5Canonical DebianIcoutils Project+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a...Show more |
4Fedoraproject OpensusePhp Gettext Project+1 more4Enterprise Linux FedoraLeap+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. |
3Fedoraproject RedhatReviewboard4Djblets Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. |
3Debian RedhatSudo Project4Debian Linux Enterprise LinuxShadow+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more |
3Isc OpensuseRedhat19Dhcpd Enterprise LinuxEnterprise Linux Desktop+16 moreJun 17, 2026 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but t...Show more |