VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2019-1010238CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.06

    Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is:…

  • CVE-2019-12838CriJul 11, 2019
    risk 0.64cvss 9.8epss 0.03

    SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.

  • CVE-2019-7165CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.04

    A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.

  • CVE-2019-11356CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.08

    The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.

  • CVE-2019-0228CriApr 17, 2019
    risk 0.64cvss 9.8epss 0.09

    Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF.

  • CVE-2019-0160CriMar 27, 2019
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.

  • CVE-2019-9898CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.03

    Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

  • CVE-2019-9895CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.02

    In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.

  • CVE-2019-9687CriMar 11, 2019
    risk 0.64cvss 9.8epss 0.02

    PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.

  • CVE-2019-9631CriMar 8, 2019
    risk 0.64cvss 9.8epss 0.03

    Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.

  • CVE-2019-3464CriFeb 6, 2019
    risk 0.64cvss 9.8epss 0.05

    Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

  • CVE-2019-3463CriFeb 6, 2019
    risk 0.64cvss 9.8epss 0.05

    Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.

  • CVE-2018-18408CriOct 17, 2018
    risk 0.64cvss 9.8epss 0.02

    A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.

  • CVE-2018-17825CriOct 1, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.

  • CVE-2018-10771CriMay 7, 2018
    risk 0.64cvss 9.8epss 0.03

    Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2018-10753CriMay 5, 2018
    risk 0.64cvss 9.8epss 0.03

    Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2014-3005CriFeb 1, 2018
    risk 0.64cvss 9.8epss 0.05

    XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.

  • CVE-2015-7687CriOct 16, 2017
    risk 0.64cvss 9.8epss 0.04

    Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.

  • CVE-2017-12170CriSep 21, 2017
    risk 0.64cvss 9.8epss 0.01

    Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding…

  • CVE-2017-11462CriSep 13, 2017
    risk 0.64cvss 9.8epss 0.05

    Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

Page 11 of 268