CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical GnuNetapp4Binutils Hci Management NodeSolidfire+1 moreJun 17, 2026 Feb 24, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls. |
4Canonical F5Gnu+1 more4Binutils Element Software ManagementTraffix Signaling Delivery Controller+1 moreJun 17, 2026 Feb 24, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls. |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in ba...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when su...Show more |
4Canonical DebianNetapp+1 more4Debian Linux PhpStorage Automation Store+1 moreJun 17, 2026 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can allow a hostile DNS server to cause PHP to misuse memcpy, leading to read...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read al...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or...Show more |
4Canonical LinuxNetapp+1 more7Cn1610 Firmware Hci Management NodeLeap+4 moreJun 17, 2026 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd re...Show more |
3Canonical LinuxRedhat4Enterprise Linux Enterprise Linux For Real TimeLinux Kernel+1 moreNov 21, 2024 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Feb 21, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures. |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapQemu+1 moreJun 17, 2026 Feb 19, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could e...Show more |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Feb 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. |
4Canonical DebianFile Project+1 more4Debian Linux FileLeap+1 moreJun 17, 2026 Feb 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact. |
4Apple CanonicalFile Project+1 more7File Iphone OsLeap+4 moreJun 17, 2026 Feb 18, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. |
4Canonical DebianFile Project+1 more4Debian Linux FileLeap+1 moreJun 17, 2026 Feb 18, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. |
2Canonical File Project2File Ubuntu LinuxJun 17, 2026 Feb 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. |
3Canonical DebianSound Exchange Project3Debian Linux Sound ExchangeUbuntu LinuxJun 17, 2026 Feb 15, 2019 N/A· v4 5.0 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-...Show more |
5Canonical DebianF5+2 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreJun 17, 2026 Feb 15, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. |
3Canonical GnomeOracle3Gnome Keyring Ubuntu LinuxZfs Storage Appliance KitNov 21, 2024 Feb 12, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext. |
13Apache CanonicalD2iq+10 more19Backports Sle Container Development KitDc/os+16 moreJun 17, 2026 Feb 11, 2019 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as r...Show more |