CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Libraw2Libraw Ubuntu LinuxJun 17, 2026 Dec 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An error within the "rollei_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash. |
2Canonical Libraw2Libraw Ubuntu LinuxJun 17, 2026 Dec 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-bounds read memory access and subsequently cause a crash. |
4Canonical DebianLibraw+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Dec 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can be exploited to cause an out-of-bounds read memory access and subseque...Show more |
4Canonical DebianLibraw+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Dec 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An error within the "LibRaw::unpack()" function (src/libraw_cxx.cpp) in LibRaw versions prior to 0.18.7 can be exploited to trigger a NULL pointer dereference. |
4Canonical DebianLibraw+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Dec 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a cras...Show more |
2Canonical Libraw2Libraw Ubuntu LinuxNov 21, 2024 Dec 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service cond...Show more |
2Canonical Libraw2Libraw Ubuntu LinuxNov 21, 2024 Dec 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially...Show more |
5Canonical DebianNetapp+2 more8Debian Linux E Series Santricity Os ControllerEnterprise Linux+5 moreNov 21, 2024 Dec 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
6Apple CanonicalDebian+3 more9Debian Linux E Series Santricity Os ControllerEnterprise Linux+6 moreNov 21, 2024 Dec 7, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. |
8Apple CanonicalDebian+5 more18Debian Linux E Series Santricity Os ControllerEnterprise Linux+15 moreNov 21, 2024 Dec 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
3Canonical GnuNetapp3Binutils Ubuntu LinuxVasa ProviderNov 21, 2024 Dec 7, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the numb...Show more |
4Canonical GoogleLinux+1 more9Android Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Dec 6, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for...Show more |
5Canonical DebianNetapp+2 more8Debian Linux E Series Santricity Os ControllerEnterprise Linux+5 moreNov 21, 2024 Dec 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Dec 4, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to users...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio...Show more |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapUbuntu Linux+1 moreNov 21, 2024 Dec 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because Wa...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Dec 3, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card....Show more |
3Canonical DebianPolkit Project3Debian Linux PolkitUbuntu LinuxNov 21, 2024 Dec 3, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command. |
3Canonical DebianLxml3Debian Linux LxmlUbuntu LinuxDec 18, 2025 Dec 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j...Show more |
3Canonical DebianFreerdp3Debian Linux FreerdpUbuntu LinuxJun 17, 2026 Nov 29, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault). |