CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxLeap+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE co...Show more |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxLeap+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands. |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxLeap+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code...Show more |
3Debian OpensuseVirglrenderer Project3Debian Linux LeapVirglrendererJun 17, 2026 Dec 23, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed commands. |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
4Debian FedoraprojectPhp+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowerc...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string cont...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti...Show more |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19...Show more |
5Canonical DebianLinux+2 more14Active Iq Unified Manager Aff Baseboard Management ControllerCloud Backup+11 moreJun 17, 2026 Dec 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that...Show more |
3Canonical DebianSa Exim Project3Debian Linux Sa EximUbuntu LinuxJun 17, 2026 Dec 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a lin...Show more |
6Apache CanonicalDebian+3 more17Application Testing Suite BookkeeperCommunications Network Integrity+14 moreJun 17, 2026 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening t...Show more |
2Debian Gnome2Debian Linux Gnome KeyringNov 21, 2024 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function |
2Apple Debian2Cups Debian LinuxNov 21, 2024 Dec 20, 2019 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system |
2Debian Gnu2Debian Linux GnutlsNov 21, 2024 Dec 20, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 GnuTLS incorrectly validates the first byte of padding in CBC modes |
3Apache DebianLibreoffice3Debian Linux LibreofficeOpenofficeNov 21, 2024 Dec 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 LibreOffice and OpenOffice automatically open embedded content |
2Debian Ecryptfs2Debian Linux Ecryptfs UtilsNov 21, 2024 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation |