Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2019-12098 In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This iss… Fedora 7.6.0+ Fix from $1,9502019-05-15 HIGH 7.5 CVE-2019-8936EPSS 6% NTP through 4.2.8p12 has a NULL Pointer Dereference. Fedora 4.2.8 / 9.2+ Fix from $1,9502019-05-15 HIGH 8.8 CVE-2019-11328 An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit thi… Fedora 3.2.0+ Fix from $1,9502019-05-14 HIGH 7.5 CVE-2019-11494 In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH com… Fedora after 2.3.5.2 Fix from $1,9502019-05-08 HIGH 7.5 CVE-2019-11499 In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login component crashes if AUTH PLAIN is attempted over a TLS secured channel wit… Fedora after 2.3.5.2 Fix from $1,9502019-05-08 HIGH 8.1 CVE-2019-7443 KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain typ… Fedora 5.55.0+ Fix from $1,9502019-05-07 HIGH 7.8 CVE-2019-3843 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient s… Fedora 242+ Fix from $1,9502019-04-26 MEDIUM 6.5 CVE-2019-11474 coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an X… Fedora Patch available Fix from $1,6002019-04-23 HIGH 7.5 CVE-2019-5427 c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity… Fedora 0.9.5.4+ Fix from $1,9502019-04-22 HIGH 7.5 CVE-2019-11412 An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode… Fedora Patch available Fix from $1,9502019-04-22 CRITICAL 9.8 CVE-2019-11234EPSS 8% FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. Fedora 3.0.19+ Fix from $2,3002019-04-22 CRITICAL 9.8 CVE-2019-11235 FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is… Fedora Patch available Fix from $2,3002019-04-22 MEDIUM 6.5 CVE-2019-11372 An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a … Fedora Patch available Fix from $1,6002019-04-20 MEDIUM 6.5 CVE-2019-11373 An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash. Fedora Patch available Fix from $1,6002019-04-20 HIGH 8.1 CVE-2019-9498 The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not va… Fedora after 11.1 Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-9499 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do n… Fedora after 11.1 Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-9497 The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit. Thi… Fedora after 2.7 Fix from $1,9502019-04-17 HIGH 7.5 CVE-2019-9496 An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE conf… Fedora after 2.7 Fix from $1,9502019-04-17 MEDIUM 5.9 CVE-2019-9494 The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cach… Fedora 1.2.3-8087+ Fix from $1,6002019-04-17 MEDIUM 5.9 CVE-2019-11065 Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are u… Fedora after 5.3.1 Fix from $1,6002019-04-10 MEDIUM 5.5 CVE-2019-9133 When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly, which leads to integer unde… Fedora after 2018.12.24.14 Fix from $1,6002019-04-09 MEDIUM 6.1 CVE-2019-3870 A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files … Fedora 2.3.6-1720 / 4.9.6+ Fix from $1,6002019-04-09 MEDIUM 6.1 CVE-2019-9844 simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. Fedora 0.4.4+ Fix from $1,6002019-04-09 MEDIUM 6.5 CVE-2019-11026 FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc. Fedora No fix yet Fix from $1,6002019-04-08 HIGH 8.6 CVE-2019-10906 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. Fedora 2.10.1+ Fix from $1,9502019-04-07 HIGH 7.5 CVE-2019-3836 It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can b… Fedora 3.6.7+ Fix from $1,9502019-04-01 CRITICAL 9.8 CVE-2019-0160 Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service v… Fedora Mitigation only Fix from $2,3002019-03-27 HIGH 7.5 CVE-2018-12545EPSS 5% In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs fra… Fedora Patch available Fix from $1,9502019-03-27 HIGH 7.5 CVE-2019-3829EPSS 59% A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification… Fedora 3.6.7+ Fix from $1,9502019-03-27 HIGH 7.5 CVE-2019-3804 It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthen… Fedora 184+ Fix from $1,9502019-03-26