Vulnerabilities > Redhat > Enterprise Linux > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-19 CVE-2011-4967 Improper Input Validation vulnerability in multiple products
tog-Pegasus has a package hash collision DoS vulnerability
network
low complexity
openpegasus redhat CWE-20
7.5
2019-11-15 CVE-2011-2726 Incorrect Authorization vulnerability in multiple products
An access bypass issue was found in Drupal 7.x before version 7.5.
network
low complexity
drupal debian redhat fedoraproject CWE-863
7.5
2019-11-15 CVE-2016-5285 NULL Pointer Dereference vulnerability in multiple products
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
network
low complexity
mozilla debian redhat suse avaya CWE-476
7.5
2019-11-14 CVE-2012-1168 Improper Input Validation vulnerability in multiple products
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
network
low complexity
moodle fedoraproject redhat CWE-20
8.2
2019-11-14 CVE-2012-1156 Information Exposure Through Log Files vulnerability in multiple products
Moodle before 2.2.2 has users' private files included in course backups
network
low complexity
moodle fedoraproject redhat CWE-532
7.5
2019-11-14 CVE-2012-1155 Information Exposure vulnerability in multiple products
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
network
low complexity
moodle fedoraproject redhat debian CWE-200
7.5
2019-11-14 CVE-2011-1145 Classic Buffer Overflow vulnerability in multiple products
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
local
low complexity
unixodbc debian opensuse redhat CWE-120
7.8
2019-11-13 CVE-2010-4664 Improper Privilege Management vulnerability in multiple products
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found.
network
low complexity
consolekit-project debian redhat CWE-269
8.8
2019-11-13 CVE-2010-4661 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
7.8
2019-11-13 CVE-2010-4657 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2.
network
low complexity
php redhat debian CWE-772
7.5