CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianGnome+1 more4Debian Linux NetworkmanagerOpensuse+1 moreNov 21, 2024 Dec 26, 2019 N/A· v4 4.4 MEDIUM· v3 3.3 LOW· v2 In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network. |
5Canonical DebianLinux+2 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreJun 17, 2026 Dec 25, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f7...Show more |
7Canonical DebianFedoraproject+4 more12Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+9 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Dec 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+10 moreJun 17, 2026 Dec 24, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c. |
5Canonical DebianLinux+2 more168300 Firmware 8700 FirmwareA400 Firmware+13 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the require...Show more |
3Canonical DebianSkolelinux4Debian Edu Config Debian Lan ConfigDebian Linux+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for o...Show more |
6Apache CanonicalDebian+3 more6Debian Linux LeapOncommand System Manager+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manip...Show more |
5Apache CanonicalDebian+2 more11Agile Engineering Data Management Debian LinuxHyperion Infrastructure Technology+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string cont...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+11 moreJun 17, 2026 Dec 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that...Show more |
3Canonical DebianSa Exim Project3Debian Linux Sa EximUbuntu LinuxJun 17, 2026 Dec 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue...Show more |
6Apache CanonicalDebian+3 more17Application Testing Suite BookkeeperCommunications Network Integrity+14 moreJun 17, 2026 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t...Show more |
7Apache AppleCanonical+4 more19Bookkeeper Cyrus SaslDebian Linux+16 moreJun 17, 2026 Dec 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of Unicode characters)...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreJun 17, 2026 Dec 17, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the numb...Show more |