Vulnerabilities > Fedoraproject > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-07 | CVE-2019-14744 | OS Command Injection vulnerability in multiple products In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. | 7.8 |
2019-08-07 | CVE-2019-14734 | Out-of-bounds Write vulnerability in multiple products AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp. | 8.8 |
2019-08-07 | CVE-2019-14733 | Out-of-bounds Write vulnerability in multiple products AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp. | 8.8 |
2019-08-07 | CVE-2019-14732 | Out-of-bounds Write vulnerability in multiple products AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp. | 8.8 |
2019-08-06 | CVE-2019-14692 | Out-of-bounds Write vulnerability in multiple products AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. | 8.8 |
2019-08-06 | CVE-2019-14691 | Out-of-bounds Write vulnerability in multiple products AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp. | 8.8 |
2019-08-06 | CVE-2019-14690 | Out-of-bounds Write vulnerability in multiple products AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp. | 8.8 |
2019-08-02 | CVE-2019-10171 | Allocation of Resources Without Limits or Throttling vulnerability in multiple products It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. | 7.5 |
2019-08-01 | CVE-2019-14494 | Divide By Zero vulnerability in multiple products An issue was discovered in Poppler through 0.78.0. | 7.5 |
2019-07-31 | CVE-2019-14459 | Integer Overflow or Wraparound vulnerability in multiple products nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service). | 7.5 |