CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian LinuxNetapp+1 more7Cloud Backup Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Dec 11, 2020 N/A· v4 5.7 MEDIUM· v3 5.4 MEDIUM· v2 A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of...Show more |
3Linux NetappRedhat6Cloud Backup Enterprise LinuxEnterprise Mrg+3 moreNov 21, 2024 Dec 11, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this spec...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly r...Show more |
7Canonical DebianFedoraproject+4 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreNov 21, 2024 Jun 9, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. |
3Canonical LinuxRedhat4Enterprise Linux Enterprise MrgLinux Kernel+1 moreNov 21, 2024 May 12, 2020 N/A· v4 5.3 MEDIUM· v3 4.4 MEDIUM· v2 A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent pro...Show more |
2Linux Redhat2Enterprise Mrg Linux KernelNov 21, 2024 May 8, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impac...Show more |
2Nokogiri Redhat8Cloudforms Management Engine Enterprise MrgNokogiri+5 moreNov 21, 2024 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri before 1.5.4 is vulnerable to XXE attacks |
cumin: At installation postgresql database user created without password |
1Redhat 2Enterprise Linux Enterprise MrgNov 21, 2024 Nov 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace. |
3Debian NokogiriRedhat7Cloudforms Management Engine Debian LinuxEnterprise Mrg+4 moreNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits |
3Debian NokogiriRedhat7Cloudforms Management Engine Debian LinuxEnterprise Mrg+4 moreNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker c...Show more |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to caus...Show more |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreNov 21, 2024 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. |
4Canonical DebianLinux+1 more5Debian Linux Enterprise LinuxEnterprise Mrg+2 moreNov 21, 2024 Dec 18, 2018 N/A· v4 8.0 HIGH· v3 6.7 MEDIUM· v2 A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerabilit...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise MrgLinux KernelNov 21, 2024 Jul 30, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going ov...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Feb 9, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup. |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Jan 14, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG). |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Jan 14, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG). |
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates. |