Vulnerabilities > Fedoraproject > Fedora > 33

DATE CVE VULNERABILITY TITLE RISK
2019-12-20 CVE-2019-19917 Classic Buffer Overflow vulnerability in multiple products
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
7.8
2019-12-13 CVE-2019-19787 Out-of-bounds Write vulnerability in multiple products
ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.
local
low complexity
atasm-project fedoraproject CWE-787
7.8
2019-12-13 CVE-2019-19786 Out-of-bounds Write vulnerability in multiple products
ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.
local
low complexity
atasm-project fedoraproject CWE-787
7.8
2019-12-13 CVE-2019-19785 Out-of-bounds Write vulnerability in multiple products
ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.
local
low complexity
atasm-project fedoraproject CWE-787
7.8
2019-12-09 CVE-2019-19648 Out-of-bounds Read vulnerability in multiple products
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size.
local
low complexity
virustotal fedoraproject CWE-125
7.8
2019-11-29 CVE-2019-19451 Infinite Loop vulnerability in multiple products
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout.
local
low complexity
gnome fedoraproject opensuse CWE-835
5.5
2019-10-10 CVE-2019-17455 Out-of-bounds Read vulnerability in multiple products
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.
network
low complexity
nongnu debian canonical fedoraproject opensuse CWE-125
critical
9.8
2019-09-27 CVE-2019-8075 Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability.
network
low complexity
adobe google debian fedoraproject
7.5
2019-08-18 CVE-2019-15151 Double Free vulnerability in multiple products
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
network
low complexity
adplug-project fedoraproject CWE-415
critical
9.8
2019-08-07 CVE-2019-14734 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8