CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectFreeradius+1 more4Enterprise Linux FedoraFreeradius+1 moreJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. |
4Canonical DebianFfmpeg+1 more4Debian Linux FfmpegSuse Package Hub For Suse Linux Enterprise+1 moreJun 17, 2026 Apr 19, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have...Show more |
2Canonical Python2Ubuntu Linux Urllib3Jun 17, 2026 Apr 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations...Show more |
3Canonical ClusterlabsFedoraproject3Fedora PacemakerUbuntu LinuxJun 17, 2026 Apr 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs. |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Aus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS |
6Canonical ClusterlabsDebian+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreNov 21, 2024 Apr 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local...Show more |
6Canonical DebianNetapp+3 more6Debian Linux LeapPhp+3 moreJun 17, 2026 Apr 18, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to info...Show more |
6Canonical DebianNetapp+3 more6Debian Linux LeapPhp+3 moreJun 17, 2026 Apr 18, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to in...Show more |
3Canonical OpensuseXmltooling Project3Leap Ubuntu LinuxXmltoolingJun 17, 2026 Apr 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type t...Show more |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreJun 17, 2026 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreJun 17, 2026 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. |
7Canonical DebianFedoraproject+4 more22Active Iq Unified Manager Cloud BackupDebian Linux+19 moreJun 17, 2026 Apr 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is...Show more |
4Canonical FedoraprojectLinux+1 more11Enterprise Linux Enterprise Linux EusEnterprise Linux For Real Time+8 moreJun 17, 2026 Apr 9, 2019 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtu...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called. |
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'. |