Vulnerabilities > Fedoraproject > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-07 CVE-2019-14744 OS Command Injection vulnerability in multiple products
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction.
7.8
2019-08-07 CVE-2019-14734 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8
2019-08-07 CVE-2019-14733 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8
2019-08-07 CVE-2019-14732 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8
2019-08-06 CVE-2019-14692 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8
2019-08-06 CVE-2019-14691 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8
2019-08-06 CVE-2019-14690 Out-of-bounds Write vulnerability in multiple products
AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.
network
low complexity
adplug-project fedoraproject CWE-787
8.8
2019-08-02 CVE-2019-10171 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5.
network
low complexity
fedoraproject redhat CWE-770
7.5
2019-08-01 CVE-2019-14494 Divide By Zero vulnerability in multiple products
An issue was discovered in Poppler through 0.78.0.
7.5
2019-07-31 CVE-2019-14459 Integer Overflow or Wraparound vulnerability in multiple products
nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
network
low complexity
nfdump-project debian fedoraproject CWE-190
7.5