CVEs (128)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectLibssh+3 more7Cloud Backup Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Aug 31, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, bo...Show more |
4Fedoraproject LinuxNetapp+1 more19Cloud Backup Enterprise LinuxEnterprise Linux For Real Time+16 moreJun 17, 2026 May 6, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-boun...Show more |
2Nbdkit Project Redhat4Enterprise Linux Enterprise Linux ServerNbdkit+1 moreJun 17, 2026 Mar 18, 2021 N/A· v4 3.7 LOW· v3 2.6 LOW· v2 A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by sim...Show more |
5Fedoraproject Lldpd ProjectOpenvswitch+2 more17Enterprise Linux FedoraLldpd+14 moreJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more |
3Fedoraproject M2crypto ProjectRedhat4Enterprise Linux FedoraM2crypto+1 moreJun 17, 2026 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat fro...Show more |
2Ovirt Redhat2Ovirt Engine VirtualizationJun 17, 2026 Dec 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key. |
2Ovirt Redhat2Ovirt Engine VirtualizationJun 17, 2026 Mar 19, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an atta...Show more |
2Qemu Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Tus+3 moreNov 21, 2024 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read. |
2Python Ecdsa Project Redhat4Ceph Storage OpenstackPython Ecdsa+1 moreJun 17, 2026 Jan 2, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signatur...Show more |
1Redhat 2Ovirt Engine VirtualizationNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center |
7Canonical DebianFedoraproject+4 more15Debian Linux Element Software Management NodeEnterprise Linux+12 moreJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more |
7Canonical DebianFedoraproject+4 more39A220 Firmware A320 FirmwareA700s Firmware+36 moreJun 17, 2026 Sep 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute ar...Show more |
8Canonical DebianFedoraproject+5 more34Aff A700s Firmware Data Availability ServicesDebian Linux+31 moreJun 17, 2026 Sep 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain....Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt wi...Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state fil...Show more |
2Canonical Redhat5Enterprise Linux LibvirtUbuntu Linux+2 moreJun 17, 2026 Jul 30, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of...Show more |
6Canonical DebianLinux+3 more23A700s Firmware Active Iq Unified ManagerCn1610 Firmware+20 moreJun 17, 2026 Jun 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences. |
2Netapp Redhat6Active Iq Unified Manager Jboss Data GridOpenshift Application Runtimes+3 moreJun 17, 2026 Jun 12, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR le...Show more |
7Canonical DebianFedoraproject+4 more14Cloud Backup Converged Systems Advisor AgentDebian Linux+11 moreJun 17, 2026 Jun 7, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attack...Show more |