Search

Found 5,523 results in 783ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-19203 medium 5.5 FIX slesdebian debian rocky 2y ago RHSA-2024:0889: oniguruma security update (Moderate)
CVE-2019-16163 medium 5.5 FIX slesdebian debian rocky 2y ago RHSA-2024:0889: oniguruma security update (Moderate)
CVE-2019-13224 medium 5.5 FIX slesdebian debian rocky 2y ago RHSA-2024:0889: oniguruma security update (Moderate)
CVE-2023-5676 medium 5.5 sles rhel 2y ago RHSA-2024:0866: java-1.8.0-ibm security update (Moderate)
CVE-2023-42465 medium 5.5 FIX rhel slesdebian debian 2y ago Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling …
CVE-2023-28487 medium 5.5 FIX rhel slesdebian debian 2y ago Sudo before 1.9.13 does not escape control characters in sudoreplay output.
CVE-2023-28486 medium 5.5 FIX rhel slesdebian debian 2y ago Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-6135 medium 5.5 FIX rhel rockydebian debian 2y ago Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox <…
CVE-2020-28241 medium 5.5 FIX rockydebian debian rhel 2y ago RHSA-2024:0768: libmaxminddb security update (Moderate)
CVE-2019-19499 medium 5.5 sles rhel 2y ago RHSA-2020:4682: grafana security, bug fix, and enhancement update (Moderate)
CVE-2024-23650 medium 5.5 sles rhel rocky 2y ago Moderate: container-tools:rhel8 security update
CVE-2024-0567 medium 5.5 FIX rheldebian debian sles 2y ago Moderate: gnutls security update
CVE-2024-0553 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:0627: gnutls security update (Moderate)
CVE-2023-5981 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:0627: gnutls security update (Moderate)
CVE-2023-7104 medium 5.5 FIX rhel rocky sles 2y ago RHSA-2024:0253: sqlite security update (Moderate)
CVE-2023-47235 medium 5.5 FIX rhel rockydebian debian 2y ago An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdra…
CVE-2023-47234 medium 5.5 FIX rhel rockydebian debian 2y ago An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory …
CVE-2023-45803 medium 5.5 FIX rhel rocky sles 2y ago Moderate: container-tools:rhel8 security update
CVE-2023-45648 medium 5.5 FIX rhel slesdebian debian 2y ago Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not c…
CVE-2023-42795 medium 5.5 FIX rhel slesdebian debian 2y ago Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0…
CVE-2023-42794 medium 5.5 FIX rhel slesdebian debian 2y ago Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in pro…
CVE-2023-41080 medium 5.5 FIX rhel slesdebian debian 2y ago URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 thro…
CVE-2023-4001 medium 5.5 FIX rhel slesdebian debian 2y ago Moderate: grub2 security update
CVE-2023-38409 medium 5.5 FIX rhel rocky sles 2y ago An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_…
CVE-2023-38407 medium 5.5 FIX rhel rockydebian debian 2y ago bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
CVE-2023-38406 medium 5.5 FIX rhel rockydebian debian 2y ago bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
CVE-2023-27043 medium 5.3 5.3 FIX rhel rocky sles netapppython 2y ago Moderate: python3.11 security update
CVE-2021-35939 medium 5.5 FIX rhel rocky sles 2y ago Moderate: rpm security update
CVE-2021-35938 medium 5.5 FIX rhel rocky sles 2y ago Moderate: rpm security update
CVE-2021-35937 medium 5.5 FIX rhel rocky sles 2y ago Moderate: rpm security update
CVE-2024-21094 medium 5.5 FIX rhel rocky sles 2y ago Moderate: java-1.8.0-openjdk security update
CVE-2023-5455 medium 5.5 FIX rhel rockydebian debian 2y ago RHSA-2024:0143: idm:DL1 security update (Moderate)
CVE-2023-5388 medium 5.5 FIX rhel rockydebian debian 2y ago Moderate: nss security update
CVE-2022-48564 medium 5.5 FIX slesdebian debian rhel 2y ago read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
CVE-2022-48560 medium 5.5 FIX rocky slesdebian debian 2y ago RHSA-2024:2987: python27:2.7 security update (Moderate)
CVE-2023-6478 medium 5.5 FIX rhel slesdebian debian 3y ago A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive informat…
CVE-2023-6377 medium 5.5 FIX rhel slesdebian debian 3y ago A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege …
CVE-2023-5367 medium 5.5 FIX rhel slesdebian debian 3y ago A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty fu…
CVE-2023-4535 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: opensc security update
CVE-2023-40661 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7876: opensc security update (Moderate)
CVE-2023-40660 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7876: opensc security update (Moderate)
CVE-2023-48795 medium 5.9 5.9 FIX rhel rockydebian debian apacheopenbsdputty 3y ago The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from…
CVE-2023-54170 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: keys: Fix linking a duplicate key to a keyring's assoc_array When making a DNS query inside the kernel using dns_query(), the req…
CVE-2023-53996 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: x86/sev: Make enc_dec_hypercall() accept a size instead of npages enc_dec_hypercall() accepted a page count instead of a size, wh…
CVE-2023-53657 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ice: Don't tx before switchdev is fully configured There is possibility that ice_eswitch_port_start_xmit might be called while so…
CVE-2023-43804 medium 5.5 FIX rhel rocky sles 3y ago Moderate: python3.11-urllib3 security update
CVE-2023-39615 medium 5.5 FIX rhel rocky sles 3y ago Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function at /libxml2/SAX2.c. This vulnerability allows attackers to cause a Denial of Service (Do…
CVE-2022-44638 medium 5.5 FIX rhel sles rocky 3y ago RHSA-2024:0131: pixman security update (Moderate)
CVE-2022-24963 medium 5.5 FIX debian debian rhel sles 3y ago Moderate: apr security update
CVE-2023-36558 medium 5.5 rhel rocky 3y ago RHSA-2023:7258: dotnet6.0 security update (Moderate)
CVE-2023-36049 medium 5.5 rhel rocky 3y ago RHSA-2023:7258: dotnet6.0 security update (Moderate)
CVE-2023-4042 medium 5.5 FIX debian debian rhel 3y ago RHSA-2023:7053: ghostscript security and bug fix update (Moderate)
CVE-2023-3301 medium 5.5 FIX rockydebian debian rhel 3y ago A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could…
CVE-2020-22217 medium 5.5 FIX debian debian sles rocky 3y ago RHSA-2023:7207: c-ares security update (Moderate)
CVE-2023-54320 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: pmc: Fix memory leak in amd_pmc_stb_debugfs_open_v2() Function amd_pmc_stb_debugfs_open_v2() may be called when…
CVE-2023-54057 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid' buffer in the parse_ivrs_acpihid func…
CVE-2023-54004 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: udplite: Fix NULL pointer dereference in __sk_mem_raise_allocated(). syzbot reported [0] a null-ptr-deref in sk_get_rmem0() while…
CVE-2023-53867 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ceph: fix potential use-after-free bug when trimming caps When trimming the caps and just after the 'session->s_cap_lock' is rele…
CVE-2023-53746 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device driver The device release callback function invoked to release the matrix device …
CVE-2023-53705 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse…
CVE-2023-53623 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix swap_info_struct race between swapoff and get_swap_pages() The si->lock must be held when deleting the si from the a…
CVE-2023-53576 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: null_blk: Always check queue mode setting from configfs Make sure to check device queue mode in the null_validate_conf() and retu…
CVE-2023-53392 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device->fw_client is set to NULL. If a bus driver is reg…
CVE-2023-53292 medium 5.5 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none After grabbing q->sysfs_lock, q->elevator may become NULL b…
CVE-2023-53224 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ext4: Fix function prototype mismatch for ext4_feat_ktype With clang's kernel control flow integrity (kCFI, CONFIG_CFI_CLANG), in…
CVE-2023-53205 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change…
CVE-2023-53103 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: bonding: restore bond's IFF_SLAVE flag if a non-eth dev enslave fails syzbot reported a warning[1] where the bond device itself i…
CVE-2023-53089 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix task hung in ext4_xattr_delete_inode Syzbot reported a hung task problem: =============================================…
CVE-2023-53088 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix UaF in listener shutdown As reported by Christoph after having refactored the passive socket initialization, the mptcp…
CVE-2023-53072 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: mptcp: use the workqueue to destroy unaccepted sockets Christoph reported a UaF at token lookup time after having refactored the …
CVE-2023-53070 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: PPTT: Fix to avoid sleep in the atomic context when PPTT is absent Commit 0c80f9e165f8 ("ACPI: PPTT: Leave the table mapped…
CVE-2023-42669 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7467: samba security update (Moderate)
CVE-2023-41105 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7024: python3.11 security update (Moderate)
CVE-2023-4091 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7467: samba security update (Moderate)
CVE-2023-39976 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libqb security update
CVE-2023-39975 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: krb5 security and bug fix update
CVE-2023-3978 medium 5.5 FIX rocky rhel sles 3y ago Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
CVE-2023-3961 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7467: samba security update (Moderate)
CVE-2023-39322 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39321 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39319 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39318 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-38712 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-38711 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-38710 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-38559 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7053: ghostscript security and bug fix update (Moderate)
CVE-2023-38197 medium 5.5 FIX rhel slesdebian debian 3y ago An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
CVE-2023-3750 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libvirt security, bug fix, and enhancement update
CVE-2023-37369 medium 5.5 FIX rhel slesdebian debian 3y ago In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefi…
CVE-2023-36054 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: krb5 security and bug fix update
CVE-2023-35789 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7150: librabbitmq security update (Moderate)
CVE-2023-3576 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libtiff security update
CVE-2023-34968 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-34967 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-34966 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-34410 medium 5.5 FIX rhel slesdebian debian 3y ago An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configur…
CVE-2023-34241 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7165: cups security and bug fix update (Moderate)
CVE-2023-33460 medium 5.5 FIX rhel rockydebian debian 3y ago RHSA-2023:7057: yajl security update (Moderate)
CVE-2023-33285 medium 5.5 FIX rhel slesdebian debian 3y ago An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
CVE-2023-33204 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7010: sysstat security and bug fix update (Moderate)