CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Sqlite2Sqlite Ubuntu LinuxJun 17, 2026 May 10, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code ex...Show more |
2Canonical Google2Android Ubuntu LinuxJun 17, 2026 May 8, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional exec...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Cn1610 FirmwareDebian Linux+11 moreJun 17, 2026 May 8, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 May 7, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame_pool() fails in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c. This causes a De...Show more |
6Canonical DebianF5+3 more13Active Iq Unified Manager Debian LinuxHci Compute Node+10 moreNov 21, 2024 May 7, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 May 3, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impac...Show more |
5Canonical DebianImagemagick+2 more5Debian Linux Enterprise LinuxImagemagick+2 moreJun 17, 2026 Apr 30, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to...Show more |
2Canonical Memcached2Memcached Ubuntu LinuxJun 17, 2026 Apr 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcache...Show more |
3Canonical NetappSystemd Project6Cn1610 Firmware Hci Management NodeSnapprotect+3 moreJun 17, 2026 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the se...Show more |
4Canonical FedoraprojectNetapp+1 more7Cn1610 Firmware FedoraHci Management Node+4 moreJun 17, 2026 Apr 26, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker m...Show more |
7Canonical DebianFedoraproject+4 more14Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+11 moreJun 17, 2026 Apr 25, 2019 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly hav...Show more |
6Canonical DebianFedoraproject+3 more13Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+10 moreJun 17, 2026 Apr 24, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administra...Show more |
4Canonical DebianGstreamer+1 more4Debian Linux GstreamerGstreamer+1 moreJun 17, 2026 Apr 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing remote code execution. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreJun 17, 2026 Apr 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (appl...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Apr 23, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/lin...Show more |
6Canonical DebianHp+3 more15Debian Linux Enterprise LinuxEnterprise Linux Desktop+12 moreJun 17, 2026 Apr 23, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with netw...Show more |
4Canonical HpOracle+1 more10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreJun 17, 2026 Apr 23, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with netw...Show more |