Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Enterprise_linux
(Redhat)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-26 | CVE-2011-3632 | Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. | Debian_linux, Hardlink, Enterprise_linux | N/A | ||
2019-11-26 | CVE-2011-3631 | Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges. | Debian_linux, Hardlink, Enterprise_linux | N/A | ||
2019-11-26 | CVE-2011-3630 | Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable. | Debian_linux, Hardlink, Enterprise_linux | N/A | ||
2019-11-25 | CVE-2012-5644 | libuser has information disclosure when moving user's home directory | Debian_linux, Fedora, Libuser, Enterprise_linux | N/A | ||
2019-11-25 | CVE-2012-5630 | libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. | Fedora, Libuser, Enterprise_linux | N/A | ||
2019-11-15 | CVE-2011-2726 | An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. | Debian_linux, Drupal, Fedora, Enterprise_linux | N/A | ||
2019-11-22 | CVE-2012-0877 | PyXML: Hash table collisions CPU usage Denial of Service | Pyxml, Enterprise_linux, Enterprise_virtualization_hypervisor | N/A | ||
2019-11-22 | CVE-2015-7810 | libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files | Debian_linux, Fedora, Enterprise_linux, Libbluray | N/A | ||
2019-11-14 | CVE-2012-1168 | Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. | Fedora, Moodle, Enterprise_linux | N/A | ||
2019-11-14 | CVE-2012-1156 | Moodle before 2.2.2 has users' private files included in course backups | Fedora, Moodle, Enterprise_linux | N/A |