VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2019-8936HigMay 15, 2019
    risk 0.49cvss 7.5epss 0.06

    NTP through 4.2.8p12 has a NULL Pointer Dereference.

  • CVE-2019-11494HigMay 8, 2019
    risk 0.49cvss 7.5epss 0.02

    In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.

  • CVE-2019-11499HigMay 8, 2019
    risk 0.49cvss 7.5epss 0.03

    In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel with an unacceptable authentication message.

  • CVE-2019-5427HigApr 22, 2019
    risk 0.49cvss 7.5epss 0.05

    c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

  • CVE-2019-9496HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.05

    An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd…

  • CVE-2019-3842HigApr 9, 2019
    risk 0.49cvss 7.0epss 0.01

    In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be…

  • CVE-2019-10903HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.

  • CVE-2019-10902HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.05

    In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting strings safely.

  • CVE-2019-10901HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.

  • CVE-2019-10900HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.05

    In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown object types safely.

  • CVE-2019-10899HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.

  • CVE-2019-10898HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.05

    In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_gsup.c by rejecting an invalid Information Element length.

  • CVE-2019-10897HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.05

    In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-ieee80211.c by detecting cases in which the bit offset does not advance.

  • CVE-2019-10896HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.

  • CVE-2019-10895HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.

  • CVE-2019-10894HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.

  • CVE-2019-10906HigApr 7, 2019
    risk 0.49cvss 8.6epss 0.04

    In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

  • CVE-2018-12545HigMar 27, 2019
    risk 0.49cvss 7.5epss 0.05

    In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory…

  • CVE-2019-9897HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.03

    Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.

  • CVE-2019-9894HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.02

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

Page 91 of 268