VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2019-18423HigOct 31, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() and p2m_get_entry() to sanity check guest physical frame.…

  • CVE-2019-18422HigOct 31, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an exception occurs on an ARM system…

  • CVE-2019-17545CriOct 14, 2019
    risk 0.57cvss 9.8epss 0.03

    GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

  • CVE-2019-17042CriOct 7, 2019
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy…

  • CVE-2019-17041CriOct 7, 2019
    risk 0.57cvss 9.8epss 0.05

    An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do…

  • CVE-2019-16943CriOct 1, 2019
    risk 0.57cvss 9.8epss 0.05

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an…

  • CVE-2019-16942CriOct 1, 2019
    risk 0.57cvss 9.8epss 0.06

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and…

  • CVE-2019-14821HigSep 19, 2019
    risk 0.57cvss 8.8epss 0.01

    An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices…

  • CVE-2019-16239CriSep 17, 2019
    risk 0.57cvss 9.8epss 0.03

    process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.

  • CVE-2019-5481CriSep 16, 2019
    risk 0.57cvss 9.8epss 0.07

    Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

  • CVE-2019-16335CriSep 15, 2019
    risk 0.57cvss 9.8epss 0.05

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.

  • CVE-2019-10746CriAug 23, 2019
    risk 0.57cvss 9.8epss 0.04

    mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

  • CVE-2019-15151CriAug 18, 2019
    risk 0.57cvss 9.8epss 0.02

    AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

  • CVE-2019-14734HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.02

    AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

  • CVE-2019-14733HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.02

    AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.

  • CVE-2019-14732HigAug 7, 2019
    risk 0.57cvss 8.8epss 0.01

    AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.

  • CVE-2019-14692HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.02

    AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

  • CVE-2019-14691HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.02

    AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp.

  • CVE-2019-14690HigAug 6, 2019
    risk 0.57cvss 8.8epss 0.02

    AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.

  • CVE-2019-14379CriJul 29, 2019
    risk 0.57cvss 9.8epss 0.08

    SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.

Page 50 of 268