| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2012-6136 |
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. Published: November 20, 2019; 10:15:11 AM -0500 |
V3.1: 5.5 MEDIUM V2.0: 4.9 MEDIUM |
| CVE-2011-1028 |
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. Published: November 20, 2019; 10:15:11 AM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2011-2924 |
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. Published: November 19, 2019; 5:15:10 PM -0500 |
V3.1: 5.5 MEDIUM V2.0: 3.3 LOW |
| CVE-2011-2923 |
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print filter. Published: November 19, 2019; 4:15:11 PM -0500 |
V3.1: 5.5 MEDIUM V2.0: 3.3 LOW |
| CVE-2016-1000236 |
Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used. Published: November 19, 2019; 12:15:11 PM -0500 |
V3.1: 4.4 MEDIUM V2.0: 3.5 LOW |
| CVE-2012-6071 |
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert. Published: November 19, 2019; 12:15:11 PM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2014-5439 |
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and address space layout randomization ASLR protection mechanisms, which could let a malicious user execute arbitrary code. Published: November 19, 2019; 11:15:11 AM -0500 |
V3.1: 7.8 HIGH V2.0: 9.3 HIGH |
| CVE-2012-0843 |
uzbl: Information disclosure via world-readable cookies storage file Published: November 19, 2019; 11:15:11 AM -0500 |
V3.1: 5.5 MEDIUM V2.0: 2.1 LOW |
| CVE-2011-4968 |
nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM) Published: November 19, 2019; 11:15:11 AM -0500 |
V3.1: 4.8 MEDIUM V2.0: 5.8 MEDIUM |
| CVE-2012-0842 |
surf: cookie jar has read access from other local user Published: November 19, 2019; 10:15:10 AM -0500 |
V3.1: 5.5 MEDIUM V2.0: 2.1 LOW |
| CVE-2019-19068 |
A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6. Published: November 18, 2019; 1:15:12 AM -0500 |
V3.1: 4.6 MEDIUM V2.0: 4.9 MEDIUM |
| CVE-2019-19066 |
A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd. Published: November 18, 2019; 1:15:12 AM -0500 |
V3.1: 4.7 MEDIUM V2.0: 4.7 MEDIUM |
| CVE-2019-19062 |
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042. Published: November 18, 2019; 1:15:12 AM -0500 |
V3.1: 4.7 MEDIUM V2.0: 4.7 MEDIUM |
| CVE-2019-19056 |
A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932. Published: November 18, 2019; 1:15:12 AM -0500 |
V3.1: 4.7 MEDIUM V2.0: 4.7 MEDIUM |
| CVE-2019-19051 |
A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-6f3ef5c25cc7. Published: November 18, 2019; 1:15:11 AM -0500 |
V3.1: 5.5 MEDIUM V2.0: 4.9 MEDIUM |
| CVE-2019-19012 |
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression. Published: November 17, 2019; 1:15:11 PM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2011-2910 |
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation. Published: November 15, 2019; 12:15:12 PM -0500 |
V3.1: 6.7 MEDIUM V2.0: 7.2 HIGH |
| CVE-2011-2726 |
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. Published: November 15, 2019; 12:15:12 PM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2011-0703 |
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session. Published: November 15, 2019; 12:15:12 PM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2016-5285 |
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. Published: November 15, 2019; 11:15:10 AM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |