Vulnerabilities > Debian > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-09-03 | CVE-2019-14811 | Incorrect Authorization vulnerability in multiple products A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. | 7.8 |
2019-08-27 | CVE-2019-13486 | Out-of-bounds Write vulnerability in multiple products In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c. | 7.5 |
2019-08-27 | CVE-2019-13485 | Out-of-bounds Write vulnerability in multiple products In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c. | 7.5 |
2019-08-27 | CVE-2019-13484 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c. | 7.5 |
2019-08-27 | CVE-2019-13455 | Out-of-bounds Write vulnerability in multiple products In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c. | 7.5 |
2019-08-27 | CVE-2019-13452 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. | 7.5 |
2019-08-27 | CVE-2019-13451 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. | 7.5 |
2019-08-27 | CVE-2019-13273 | Out-of-bounds Write vulnerability in multiple products In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. | 7.5 |
2019-08-25 | CVE-2019-15538 | Resource Exhaustion vulnerability in multiple products An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. | 7.5 |
2019-08-20 | CVE-2019-10086 | Deserialization of Untrusted Data vulnerability in multiple products In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. | 7.3 |