Skip to main content

Vendor/product archive

redhat / enterprise_linux_desktop CVEs

Beta · best-effort

1,939 CVEs tagged to redhat / enterprise_linux_desktop343 Critical, 702 High, 771 Medium, 123 Low, 0 Unrated.

CVE-2019-17017

Published Jan 8, 2020

Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run…

CVSS 8.8 · High

CVE-2019-17016

Published Jan 8, 2020

When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain…

CVSS 6.1 · Medium

CVE-2019-19925

Published Dec 24, 2019

zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-19923

Published Dec 24, 2019

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer…

CVSS 7.5 · High

CVE-2019-19926

Published Dec 23, 2019

multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists bec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-1311

Published Dec 18, 2019

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ve…

CVSS 8.1 · High

CVE-2019-8506

Published Dec 18, 2019

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Win…

CVSS 8.8 · High
evidence mentions
2
Buzz score
42.5
KEV listed

CVE-2019-19880

Published Dec 18, 2019

exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definition…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-13764

Published Dec 10, 2019

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Showing 76-100 of 1,939 CVEsPage 4 of 78