SELinux Project SELinux is vulnerable to a denial of service, caused by a use-after-free in cilverifyclassperms. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service condition.
SELinux Project SELinux is vulnerable to a denial of service, caused by a heap-based buffer over-read in ebitmapmatchany. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service condition.
SELinux Project SELinux is vulnerable to a denial of service, caused by a use-after-free in cilverifyclassperms. By sending a specially-crafted request, a local attacker could exploit this vulnerability to cause a denial of service condition.
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some situations. IBM X-Force ID: 208397.
IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 220041.
An issue was discovered in GNOME GLib before 2.66.8. When gfilereplace() is used with GFILECREATEREPLACEDESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)