Vulnerabilities
Vulnerable Software
Opensuse:  Security Vulnerabilities
libopenmpt before 0.3.13 allows a crash with malformed MED files.
CVSS Score
6.5
EPSS Score
0.003
Published
2019-07-30
J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
CVSS Score
6.5
EPSS Score
0.004
Published
2019-07-30
A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.
CVSS Score
3.1
EPSS Score
0.002
Published
2019-07-30
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
CVSS Score
5.5
EPSS Score
0.003
Published
2019-07-30
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
CVSS Score
9.8
EPSS Score
0.722
Published
2019-07-29
An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)
CVSS Score
4.9
EPSS Score
0.008
Published
2019-07-26
An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL bind is completed, the sasl_ssf value is retained for all new non-SASL connections. Depending on the ACL configuration, this can affect different types of operations (searches, modifications, etc.). In other words, a successful authorization step completed by one user affects the authorization requirement for a different user.
CVSS Score
7.5
EPSS Score
0.044
Published
2019-07-26
An issue was discovered in the Linux kernel before 4.18.7. In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace.
CVSS Score
3.3
EPSS Score
0.001
Published
2019-07-26
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
CVSS Score
5.5
EPSS Score
0.002
Published
2019-07-26
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
CVSS Score
5.5
EPSS Score
0.001
Published
2019-07-26


Contact Us

Shodan ® - All rights reserved