CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openssl
1Openssl
Jun 17, 2026
Mar 6, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and...Show more
ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifies that the nonce value (IV) should be 96 bits (12 bytes). OpenSSL allows a variable nonce length and front pads the nonce with 0 bytes if it is less than 12 bytes. However it also incorrectly allows a nonce to be set of up to 16 bytes. In this case only the last 12 bytes are significant and any additional leading bytes are ignored. It is a requirement of using this cipher that nonce values are unique. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks. If an application changes the default nonce length to be longer than 12 bytes and then makes a change to the leading bytes of the nonce expecting the new value to be a new unique nonce then such an application could inadvertently encrypt messages with a reused nonce. Additionally the ignored bytes in a long nonce are not covered by the integrity guarantee of this cipher. Any application that relies on the integrity of these ignored leading bytes of a long nonce may be further affected. Any OpenSSL internal use of this cipher, including in SSL/TLS, is safe because no such use sets such a long nonce value. However user applications that use this cipher directly and set a non-default nonce length to be longer than 12 bytes may be vulnerable. OpenSSL versions 1.1.1 and 1.1.0 are affected by this issue. Due to the limited scope of affected deployments this has been assessed as low severity and therefore we are not creating new releases at this time. Fixed in OpenSSL 1.1.1c (Affected 1.1.1-1.1.1b). Fixed in OpenSSL 1.1.0k (Affected 1.1.0-1.1.0j).Show less
1Mkcms Project
1Mkcms
Jun 17, 2026
Apr 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
1Fastadmin
1Fastadmin
Jun 17, 2026
Apr 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.
1Lighttpd
1Lighttpd
Jun 17, 2026
Apr 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as dem...Show more
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer states "The feature which can be abused to cause the crash is a new feature in lighttpd 1.4.50, and is not enabled by default. It must be explicitly configured in the config file (e.g. lighttpd.conf). Certain input will trigger an abort() in lighttpd when that feature is enabled. lighttpd detects the underflow or realloc() will fail (in both 32-bit and 64-bit executables), also detected in lighttpd. Either triggers an explicit abort() by lighttpd. This is not exploitable beyond triggering the explicit abort() with subsequent application exit.Show less
2Debian
Spip
2Debian Linux
Spip
Jun 17, 2026
Apr 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
2Webkitgtk
Wpewebkit
2Webkitgtk
Wpe Webkit
Jun 17, 2026
Apr 10, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This iss...Show more
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.Show less
1Sequelizejs
1Sequelize
Jun 17, 2026
Apr 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
7Canonical
DebianFedoraproject+4 more
22Active Iq Unified Manager
Cloud BackupDebian Linux+19 more
Jun 17, 2026
Apr 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is...Show more
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.Show less
2Fedoraproject
Gradle
2Fedora
Gradle
Jun 17, 2026
Apr 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a...Show more
Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.Show less
1Gatship
1Web Module
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to the server via the "Documents" area. This vulnerability is related to "uploadDocFile.aspx".
2Fedoraproject
Freedesktop
2Fedora
Poppler
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
2Cacti
Debian
2Cacti
Debian Linux
Jun 17, 2026
Apr 8, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
2Libsixel Project
Saitoha
2Libsixel
Libsixel
Jun 17, 2026
Apr 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
1Graphviz
1Graphviz
Jun 17, 2026
Apr 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.
1Thinkadmin
1Thinkadmin
Jun 17, 2026
Apr 8, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.
1Elgg
1Elgg
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
1Vstarcam
1Eye4
Jun 17, 2026
Apr 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS, and Windows), do not prevent spoofing of the camera server. An attacker can create a fake camera ser...Show more
The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS, and Windows), do not prevent spoofing of the camera server. An attacker can create a fake camera server that listens for the client looking for a camera on the local network. When the camera responds to the client, it responds via the broadcast address, giving all information necessary to impersonate the camera. The attacker then floods the client with responses, causing the original camera to be denied service from the client, and thus causing the client to then communicate exclusively with the attacker's fake camera server. When connecting to the fake camera server, the client sends all details necessary to login to the camera (username and password).Show less
3Debian
GraphicsmagickOpensuse
3Debian Linux
GraphicsmagickLeap
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
3Debian
GraphicsmagickOpensuse
3Debian Linux
GraphicsmagickLeap
Jun 17, 2026
Apr 8, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted...Show more
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.Show less
4Canonical
DebianGraphicsmagick+1 more
5Backports Sle
Debian LinuxGraphicsmagick+2 more
Jun 17, 2026
Apr 8, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly...Show more
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.Show less
4Canonical
DebianGraphicsmagick+1 more
5Backports Sle
Debian LinuxGraphicsmagick+2 more
Jun 17, 2026
Apr 8, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image...Show more
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.Show less
3Debian
GraphicsmagickOpensuse
3Debian Linux
GraphicsmagickLeap
Jun 17, 2026
Apr 8, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE...Show more
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet.Show less
2Graphicsmagick
Opensuse
2Graphicsmagick
Leap
Jun 17, 2026
Apr 8, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possib...Show more
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.Show less
1Materializecss
1Materialize
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Materialize through 1.0.0, XSS is possible via the Toast feature.
1Materializecss
1Materialize
Jun 17, 2026
Apr 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature.