Vulnerabilities > Redhat > Enterprise Linux > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2012-1155 Information Exposure vulnerability in multiple products
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
network
low complexity
moodle fedoraproject redhat debian CWE-200
7.5
2019-11-14 CVE-2011-1145 Classic Buffer Overflow vulnerability in multiple products
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
local
low complexity
unixodbc debian opensuse redhat CWE-120
7.8
2019-11-13 CVE-2010-4664 Improper Privilege Management vulnerability in multiple products
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found.
network
low complexity
consolekit-project debian redhat CWE-269
8.8
2019-11-13 CVE-2010-4661 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
7.8
2019-11-13 CVE-2010-4657 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2.
network
low complexity
php redhat debian CWE-772
7.5
2019-11-04 CVE-2017-5333 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
7.8
2019-11-04 CVE-2017-5332 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
7.8
2019-11-04 CVE-2013-4251 Improper Privilege Management vulnerability in multiple products
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
local
low complexity
scipy fedoraproject redhat debian CWE-269
7.8
2019-11-04 CVE-2005-4890 Improper Input Validation vulnerability in multiple products
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program".
local
low complexity
sudo-project debian redhat CWE-20
7.8
2019-11-01 CVE-2013-4751 Improper Input Validation vulnerability in multiple products
php-symfony2-Validator has loss of information during serialization
network
low complexity
sensiolabs fedoraproject redhat CWE-20
8.1