CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Apache AppleCanonical+4 more19Bookkeeper Cyrus SaslDebian Linux+16 moreJun 17, 2026 Dec 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more |
5Apache DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 4, 2025 Dec 18, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current m...Show more |
8Debian NetappOpensuse+5 more11Backports Sle Cloud BackupDebian Linux+8 moreJun 17, 2026 Dec 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. |
2Debian Mahara2Debian Linux MaharaNov 21, 2024 Dec 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as use...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreJun 17, 2026 Dec 17, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-of-bounds write access in __btrfs_map_block in fs/btrfs/volumes.c, because a value of 1 for the numb...Show more |
4Canonical DebianLinux+1 more13Active Iq Unified Manager Aff A400 FirmwareAff A700s Firmware+10 moreJun 17, 2026 Dec 17, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is rela...Show more |
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Dec 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database. |
3Debian Excon ProjectOpensuse4Backports Sle Debian LinuxExcon+1 moreJul 28, 2026 Dec 16, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read...Show more |
2Debian Nic2Debian Linux Knot ResolverJun 17, 2026 Dec 16, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several...Show more |
4Canonical CyrusDebian+1 more4Debian Linux FedoraImap+1 moreJun 17, 2026 Dec 16, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail acc...Show more |
2Debian Requests Kerberos Project2Debian Linux Requests KerberosNov 21, 2024 Dec 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-requests-Kerberos through 0.5 does not handle mutual authentication |
2Debian Imagemagick2Debian Linux ImagemagickNov 21, 2024 Dec 15, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 imagemagick 6.8.9.6 has remote DOS via infinite loop |
2Debian Zend2Debian Linux Zend FrameworkNov 21, 2024 Dec 15, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ZF2014-03 has a potential cross site scripting vector in multiple view helpers |
3Debian FedoraprojectXfig Project3Debian Linux FedoraFig2devJun 17, 2026 Dec 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. |
2Debian Opensuse3Debian Linux DuplicityOpensuseNov 21, 2024 Dec 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 duplicity 0.6.24 has improper verification of SSL certificates |
3Debian OpensusePen Project3Debian Linux OpensusePenNov 21, 2024 Dec 13, 2019 N/A· v4 4.4 MEDIUM· v3 4.6 MEDIUM· v2 Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities |
3Debian PuppetRedhat3Debian Linux Marionette CollectiveOpenshiftNov 21, 2024 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mcollective has a default password set at install |
2Apache Debian2Debian Linux SpamassassinJun 17, 2026 Dec 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. |
2Apache Debian2Debian Linux SpamassassinNov 21, 2024 Dec 12, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA...Show more |
2Davical Debian2Davical Debian LinuxJun 17, 2026 Dec 12, 2019 N/A· v4 9.3 CRITICAL· v3 4.3 MEDIUM· v2 A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as we...Show more |