Vulnerabilities
Vulnerable Software
Fedoraproject:  >> Fedora  >> 19  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
CVSS Score
6.1
EPSS Score
0.006
Published
2019-11-01
php-symfony2-Validator has loss of information during serialization
CVSS Score
8.1
EPSS Score
0.006
Published
2019-11-01
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial of service (DoS). Versions 3.10, 4.14 and 4.18 are vulnerable.
CVSS Score
4.7
EPSS Score
0.0
Published
2019-04-24
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
CVSS Score
9.8
EPSS Score
0.173
Published
2019-04-22
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.004
Published
2018-04-10
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.003
Published
2018-04-10
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.004
Published
2018-04-10
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
CVSS Score
7.8
EPSS Score
0.0
Published
2018-02-09
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
CVSS Score
9.8
EPSS Score
0.045
Published
2018-02-01
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
CVSS Score
5.5
EPSS Score
0.0
Published
2018-01-08


Contact Us

Shodan ® - All rights reserved