CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianFreedesktop3Debian Linux PopplerUbuntu LinuxNov 21, 2024 Dec 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag i...Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreNov 21, 2024 Dec 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service...Show more |
3Canonical FedoraprojectQemu3Fedora QemuUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference). |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value. |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 QEMU can have an infinite loop in hw/rdma/vmw/pvrdma_dev_ring.c because return values are not checked (and -1 is mishandled). |
3Canonical OpensuseQemu3Leap QemuUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled. |
2Canonical Qemu2Qemu Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings. |
4Canonical FedoraprojectLibarchive+1 more4Fedora LeapLibarchive+1 moreNov 21, 2024 Dec 20, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc....Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes...Show more |
3Canonical GnuRedhat5Binutils Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Dec 20, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successf...Show more |
2Canonical Gnupg2Gnupg Ubuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim...Show more |
3Canonical FedoraprojectFreerdp3Fedora FreerdpUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that...Show more |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxJun 17, 2026 Dec 19, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution. |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxNov 21, 2024 Dec 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS. |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxNov 21, 2024 Dec 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclo...Show more |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxNov 21, 2024 Dec 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for informa...Show more |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxNov 21, 2024 Dec 19, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM |
3Canonical DebianLibvnc Project3Debian Linux LibvncserverUbuntu LinuxNov 21, 2024 Dec 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution |
4Canonical DebianLibvnc Project+1 more9Debian Linux LibvncserverSimatic Itc1500 Firmware+6 moreNov 21, 2024 Dec 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution |