Skip to main content

Vendor/product archive

clusterlabs / libqb CVEs

Beta · best-effort

2 CVEs tagged to clusterlabs / libqb1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-39976

Published Aug 8, 2023

log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12779

Published Jun 7, 2019

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1