CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLinux+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Oct 3, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxNov 21, 2024 Oct 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Sep 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service. |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxDec 3, 2025 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field d...Show more |
3Canonical DebianStrongswan3Debian Linux StrongswanUbuntu LinuxDec 3, 2025 Sep 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PK...Show more |
6Canonical F5Linux+3 more28Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+25 moreJan 27, 2026 Sep 25, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on t...Show more |
5Apache CanonicalNetapp+2 more9Enterprise Linux Enterprise Manager Ops CenterHospitality Guest Access+6 moreNov 21, 2024 Sep 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Sep 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause...Show more |
4Canonical DebianLinux+1 more8Debian Linux Enterprise Linux EusEnterprise Linux Server+5 moreNov 21, 2024 Sep 25, 2018 N/A· v4 7.0 HIGH· v3 8.3 HIGH· v2 A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker...Show more |
3Canonical DebianTug3Debian Linux Tex LiveUbuntu LinuxNov 21, 2024 Sep 23, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font i...Show more |
2Canonical Freedesktop2Ubuntu Linux UdisksNov 21, 2024 Sep 22, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspec...Show more |
3Canonical HaproxyRedhat5Enterprise Linux HaproxyOpenshift+2 moreNov 21, 2024 Sep 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service. |
3Canonical LiblouisOpensuse3Leap LiblouisUbuntu LinuxNov 21, 2024 Sep 21, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by...Show more |
4Canonical DebianOpenvswitch+1 more4Debian Linux OpenstackOpenvswitch+1 moreNov 21, 2024 Sep 19, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding. |
3Canonical OpenvswitchRedhat3Openstack OpenvswitchUbuntu LinuxNov 21, 2024 Sep 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow c...Show more |
4Canonical DebianOpenvswitch+1 more4Debian Linux OpenstackOpenvswitch+1 moreNov 21, 2024 Sep 19, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole gro...Show more |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Sep 19, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code. |
4Canonical DebianLinux+1 more5Active Iq Performance Analytics Services Debian LinuxElement Software+2 moreNov 21, 2024 Sep 19, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) v...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPython+1 moreNov 21, 2024 Sep 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that c...Show more |
4Apache CanonicalDebian+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Sep 17, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. |