RSS   Podatności dla 'Enterprise linux'   RSS

2019-11-25
 
CVE-2019-14822

CWE-862
 

 
A flaw was discovered in ibus that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

 
 
CVE-2019-14815

CWE-787
 

 
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.

 
 
CVE-2012-5644

CWE-200
 

 
libuser has information disclosure when moving user's home directory

 
 
CVE-2012-5630

CWE-367
 

 
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.

 
2019-11-26
 
CVE-2011-3632

CWE-59
 

 
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.

 
 
CVE-2011-3631

CWE-190
 

 
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.

 
 
CVE-2011-3630

CWE-787
 

 
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.

 
2019-11-22
 
CVE-2015-7810

CWE-367
 

 
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

 
 
CVE-2014-3585

CWE-347
 

 
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions

 
2019-11-20
 
CVE-2013-1817

CWE-200
 

 
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.

 


Copyright 2019, cxsecurity.com

 

Back to Top