CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |
8Apache CanonicalDebian+5 more14Clustered Data Ontap Debian LinuxEnterprise Linux+11 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing config...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 8, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 8, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image...Show more |
5Canonical FedoraprojectOpensuse+2 more5Fedora JinjaLeap+2 moreJun 17, 2026 Apr 7, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. |
2Canonical Nvidia17Geforce Gtx 745 Firmware Geforce Gtx 750 FirmwareGeforce Gtx 750 Ti Firmware+14 moreNov 21, 2024 Apr 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-s...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Apr 1, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxJun 17, 2026 Mar 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file. |
2Burrow Wheeler Aligner Project Canonical2Burrow Wheeler Aligner Ubuntu LinuxJun 17, 2026 Mar 29, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file. |
4Canonical DebianDovecot+1 more4Debian Linux DovecotLeap+1 moreJun 17, 2026 Mar 28, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more4Enterprise Linux FedoraMod Auth Mellon+1 moreJun 17, 2026 Mar 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert...Show more |
2Canonical Ceph2Civetweb Ubuntu LinuxJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors fo...Show more |
3Canonical DovecotOpensuse3Dovecot LeapUbuntu LinuxJun 17, 2026 Mar 27, 2019 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a valid certificate with an empty username field could possibly use this iss...Show more |
3Canonical FedoraprojectZnc3Fedora Ubuntu LinuxZncJun 17, 2026 Mar 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding. |
4Canonical FedoraprojectMod Auth Mellon Project+1 more10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Mar 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), a...Show more |
5Canonical DebianLinux+2 more9Active Iq Unified Manager For Vmware Vsphere Cn1610 FirmwareDebian Linux+6 moreJun 17, 2026 Mar 25, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vu...Show more |
3Canonical DebianXpdfreader3Debian Linux Ubuntu LinuxXpdfJun 17, 2026 Mar 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case. |
6Canonical DebianFedoraproject+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreJun 17, 2026 Mar 23, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('l...Show more |
5Canonical DebianGnu+2 more6Bash Debian LinuxHci Management Node+3 moreJun 17, 2026 Mar 22, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 21, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more |