Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Fedora
(Fedoraproject)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-06 | CVE-2019-14833 | A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory Domain Controller can be configured to use a custom script to check for password complexity. This configuration can fail to verify password complexity when non-ASCII characters are used in the password, which could lead to weak passwords being set for samba users, making it... | Fedora, Leap, Samba | 5.4 | ||
2019-11-06 | CVE-2019-14847 | A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue. | Fedora, Leap, Samba | 4.9 | ||
2019-11-06 | CVE-2016-1000037 | Pagure: XSS possible in file attachment endpoint | Fedora, Enterprise_linux, Pagure | 6.1 | ||
2019-11-07 | CVE-2019-18804 | DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp. | Ubuntu_linux, Debian_linux, Djvulibre, Fedora, Leap | 7.5 | ||
2019-11-07 | CVE-2019-18808 | A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247. | Ubuntu_linux, Fedora, Linux_kernel, Leap | 5.5 | ||
2019-11-07 | CVE-2019-18809 | A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559. | Ubuntu_linux, Debian_linux, Fedora, Linux_kernel, Leap | 4.6 | ||
2019-11-07 | CVE-2019-18811 | A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1. | Fedora, Linux_kernel, Enterprise_linux | 5.5 | ||
2019-11-11 | CVE-2019-18849 | In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup. | Ubuntu_linux, Debian_linux, Fedora, Tnef | 5.5 | ||
2019-11-13 | CVE-2019-18837 | An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c. | Crun, Fedora | 8.6 | ||
2019-11-14 | CVE-2019-14818 | A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition. | Data_plane_development_kit, Fedora, Enterprise_linux_fast_datapath, Openstack, Virtualization_eus | 7.5 |