Skip to main content

Vendor/product archive

redhat / enterprise_linux_workstation CVEs

Beta · best-effort

1,835 CVEs tagged to redhat / enterprise_linux_workstation326 Critical, 690 High, 718 Medium, 101 Low, 0 Unrated.

CVE-2015-3147

Published Jan 14, 2020

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or pos…

CVSS 6.5 · Medium

CVE-2020-6851

Published Jan 13, 2020

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

CVSS 7.5 · High

CVE-2019-17024

Published Jan 8, 2020

Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough…

CVSS 8.8 · High

CVE-2019-17022

Published Jan 8, 2020

When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted dir…

CVSS 6.1 · Medium

CVE-2019-17017

Published Jan 8, 2020

Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run…

CVSS 8.8 · High

CVE-2019-17016

Published Jan 8, 2020

When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain…

CVSS 6.1 · Medium

CVE-2019-19925

Published Dec 24, 2019

zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-19923

Published Dec 24, 2019

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer…

CVSS 7.5 · High

CVE-2019-19926

Published Dec 23, 2019

multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists bec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-1311

Published Dec 18, 2019

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ve…

CVSS 8.1 · High
Showing 76-100 of 1,835 CVEsPage 4 of 74