CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical MariadbNetapp+1 more7Active Iq Unified Manager MariadbMysql+4 moreNov 21, 2024 Apr 19, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Apr 19, 2018 N/A· v4 7.7 HIGH· v3 3.7 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vuln...Show more |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause...Show more |
3Canonical DebianPerl3Debian Linux PerlUbuntu LinuxJun 17, 2026 Apr 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count. |
4Canonical DebianPerl+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Apr 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure. |
4Canonical DebianPerl+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Apr 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Apr 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick 7.0.7-28, there is an infinite loop in the ReadOneMNGImage function of the coders/png.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted mng file. |
2Canonical Openssl2Openssl Ubuntu LinuxNov 21, 2024 Apr 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Apr 16, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument. |
4Canonical DebianLibreoffice+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Apr 16, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of ser...Show more |
4Canonical DebianLibreoffice+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Apr 16, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-fre...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Apr 13, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of th...Show more |
4Canonical CorosyncDebian+1 more4Corosync Debian LinuxEnterprise Linux Server+1 moreNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
3Canonical RedhatZsh5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Apr 11, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user. |
2Canonical Qpdf Project2Qpdf Ubuntu LinuxJun 17, 2026 Apr 10, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and...Show more |
4Canonical DebianGnu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreApr 14, 2025 Apr 6, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via...Show more |
3Canonical DebianGoogle3Android Debian LinuxUbuntu LinuxNov 21, 2024 Apr 4, 2018 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974. |
2Canonical Gnupg2Gnupg Ubuntu LinuxJun 17, 2026 Apr 4, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subke...Show more |
3Canonical DebianNcmpc Project3Debian Linux NcmpcUbuntu LinuxJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur. |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxJun 17, 2026 Apr 3, 2018 N/A· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding...Show more |