CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianEclipse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Sep 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then...Show more |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers. |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character. |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages. |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_actio...Show more |
8Canonical DebianFedoraproject+5 more34Aff A700s Firmware Data Availability ServicesDebian Linux+31 moreJun 17, 2026 Sep 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpendmarc+1 moreJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin o...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes. |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 13, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardw...Show more |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 13, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transa...Show more |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreJun 17, 2026 Sep 12, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala. |
3Canonical LinuxOpensuse3Leap Linux KernelUbuntu LinuxJun 17, 2026 Sep 11, 2019 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. |
4Canonical FedoraprojectLinux+1 more4Fedora LeapLinux Kernel+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being...Show more |
8Canonical DebianFedoraproject+5 more20Active Iq Unified Manager Communications Design StudioDebian Linux+17 moreJun 17, 2026 Sep 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." |