Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2019
gnome-system-log polkit policy allows arbitrary files on the system to be read
CVSS Score
7.5
EPSS Score
0.005
Published
2019-11-25
opendnssec misuses libcurl API
CVSS Score
9.8
EPSS Score
0.006
Published
2019-11-25
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
CVSS Score
7.8
EPSS Score
0.001
Published
2019-11-25
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
CVSS Score
6.3
EPSS Score
0.001
Published
2019-11-25
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
CVSS Score
4.7
EPSS Score
0.002
Published
2019-11-25
Python keyring has insecure permissions on new databases allowing world-readable files to be created
CVSS Score
6.2
EPSS Score
0.001
Published
2019-11-25
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
CVSS Score
7.1
EPSS Score
0.001
Published
2019-11-25
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
CVSS Score
6.4
EPSS Score
0.002
Published
2019-11-25
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
CVSS Score
7.8
EPSS Score
0.001
Published
2019-11-25
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
CVSS Score
5.0
EPSS Score
0.003
Published
2019-11-25


Contact Us

Shodan ® - All rights reserved