CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectOracle+1 more5Fedora SolarisTwisted+2 moreJun 17, 2026 Jun 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF. |
3Canonical DebianGoogle3Android Debian LinuxUbuntu LinuxJun 17, 2026 Jun 7, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User...Show more |
7Canonical DebianFedoraproject+4 more14Cloud Backup Converged Systems Advisor AgentDebian Linux+11 moreJun 17, 2026 Jun 7, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attack...Show more |
3Canonical DebianExim3Debian Linux EximUbuntu LinuxJun 17, 2026 Jun 5, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution. |
5Canonical FedoraprojectLinux+2 more5Enterprise Linux FedoraLeap+2 moreJun 17, 2026 Jun 3, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial...Show more |
5Canonical CyrusDebian+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Jun 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. |
7Canonical DebianFedoraproject+4 more12A700s Firmware Active Iq Unified Manager For Vmware VsphereCn1610 Firmware+9 moreJun 17, 2026 Jun 3, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network. |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapSqlite+1 moreJun 17, 2026 May 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables. |
6Canonical DebianFedoraproject+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreJun 17, 2026 May 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. |
4Canonical FedoraprojectGnome+1 more4Fedora GvfsLeap+1 moreJun 17, 2026 May 29, 2019 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file://...Show more |
4Canonical FedoraprojectGnome+1 more4Fedora GvfsLeap+1 moreJun 17, 2026 May 29, 2019 N/A· v4 7.3 HIGH· v3 4.9 MEDIUM· v2 An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used. |
6Canonical DebianGoogle+3 more7Backports ChromeDebian Linux+4 moreJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
4Canonical DebianF5+1 more16Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+13 moreJun 17, 2026 May 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion. |
5Canonical DebianFedoraproject+2 more7Backports Sle Debian LinuxFedora+4 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c. |
4Canonical DebianFedoraproject+1 more5Debian Linux FedoraSdl2 Image+2 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a heap-based buffer overflow in the SDL2_image function IMG_LoadPCX...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFreeimage+1 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, leading to stack exhaustion. |
2Canonical Freeimage Project2Freeimage Ubuntu LinuxJun 17, 2026 May 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulti...Show more |
6Artifex CanonicalDebian+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 May 16, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have acces...Show more |
5Canonical DebianFedoraproject+2 more15Debian Linux Enterprise LinuxEnterprise Linux Desktop+12 moreJun 17, 2026 May 15, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the...Show more |
6Canonical DebianFedoraproject+3 more12Debian Linux Enterprise LinuxEnterprise Linux Eus+9 moreJun 17, 2026 May 10, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a...Show more |