Fedora
CVEs (5,359)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19797 | Med | 0.36 | 5.5 | 0.01 | Dec 15, 2019 | read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. | ||
| CVE-2019-19746 | Med | 0.36 | 5.5 | 0.01 | Dec 12, 2019 | make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type. | ||
| CVE-2019-1551 | Med | 0.36 | 5.3 | 0.14 | Dec 6, 2019 | There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult… | ||
| CVE-2012-1105 | Med | 0.36 | 5.5 | 0.00 | Dec 5, 2019 | An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner. | ||
| CVE-2019-19451 | Med | 0.36 | 5.5 | 0.00 | Nov 29, 2019 | When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to… | ||
| CVE-2012-5644 | Med | 0.36 | 5.5 | 0.00 | Nov 25, 2019 | libuser has information disclosure when moving user's home directory | ||
| CVE-2012-6136 | Med | 0.36 | 5.5 | 0.00 | Nov 20, 2019 | tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. | ||
| CVE-2011-2924 | Med | 0.36 | 5.5 | 0.00 | Nov 19, 2019 | foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible… | ||
| CVE-2014-5118 | Med | 0.36 | 5.5 | 0.00 | Nov 18, 2019 | Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability | ||
| CVE-2010-4177 | Med | 0.36 | 5.5 | 0.00 | Nov 12, 2019 | mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes. | ||
| CVE-2013-1820 | Med | 0.36 | 5.5 | 0.00 | Nov 8, 2019 | tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. | ||
| CVE-2010-4178 | Med | 0.36 | 5.5 | 0.00 | Nov 6, 2019 | MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console | ||
| CVE-2019-2991 | Med | 0.36 | 5.5 | 0.02 | Oct 16, 2019 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.017 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL… | ||
| CVE-2019-15145 | Med | 0.36 | 5.5 | 0.02 | Aug 18, 2019 | DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in… | ||
| CVE-2019-15144 | Med | 0.36 | 5.5 | 0.02 | Aug 18, 2019 | In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h. | ||
| CVE-2019-15143 | Med | 0.36 | 5.5 | 0.02 | Aug 18, 2019 | In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp. | ||
| CVE-2019-15142 | Med | 0.36 | 5.5 | 0.02 | Aug 18, 2019 | In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file. | ||
| CVE-2019-14464 | Med | 0.36 | 5.5 | 0.01 | Jul 31, 2019 | XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow. | ||
| CVE-2019-2805 | Med | 0.36 | 6.5 | 0.04 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via… | ||
| CVE-2019-2740 | Med | 0.36 | 6.5 | 0.04 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via… |
- risk 0.36cvss 5.5epss 0.01
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
- risk 0.36cvss 5.5epss 0.01
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
- risk 0.36cvss 5.3epss 0.14
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult…
- risk 0.36cvss 5.5epss 0.00
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.
- risk 0.36cvss 5.5epss 0.00
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to…
- risk 0.36cvss 5.5epss 0.00
libuser has information disclosure when moving user's home directory
- risk 0.36cvss 5.5epss 0.00
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
- risk 0.36cvss 5.5epss 0.00
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…
- risk 0.36cvss 5.5epss 0.00
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
- risk 0.36cvss 5.5epss 0.00
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
- risk 0.36cvss 5.5epss 0.00
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
- risk 0.36cvss 5.5epss 0.00
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
- risk 0.36cvss 5.5epss 0.02
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.017 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…
- risk 0.36cvss 5.5epss 0.02
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in…
- risk 0.36cvss 5.5epss 0.02
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
- risk 0.36cvss 5.5epss 0.02
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
- risk 0.36cvss 5.5epss 0.02
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
- risk 0.36cvss 5.5epss 0.01
XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
- risk 0.36cvss 6.5epss 0.04
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via…
- risk 0.36cvss 6.5epss 0.04
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via…
Page 161 of 268