Skip to main content

Vendor/product archive

redhat / enterprise_linux_desktop CVEs

Beta · best-effort

1,939 CVEs tagged to redhat / enterprise_linux_desktop343 Critical, 702 High, 771 Medium, 123 Low, 0 Unrated.

CVE-2019-13732

Published Dec 10, 2019

Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-13730

Published Dec 10, 2019

Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-13729

Published Dec 10, 2019

Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-13728

Published Dec 10, 2019

Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-13727

Published Dec 10, 2019

Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-10216

Published Nov 27, 2019

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could ab…

CVSS 7.8 · High

CVE-2017-5333

Published Nov 4, 2019

Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process cras…

CVSS 7.8 · High

CVE-2017-5332

Published Nov 4, 2019

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (proces…

CVSS 7.8 · High

CVE-2019-14287

Published Oct 17, 2019

In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invo…

CVSS 8.8 · High
evidence mentions
3
Buzz score
29.7
Public PoC observed

CVE-2019-2989

Published Oct 16, 2019

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Ja…

CVSS 6.8 · Medium
Showing 126-150 of 1,939 CVEsPage 6 of 78