CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Python2Debian Linux KeyringNov 21, 2024 Oct 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python keyring lib before 0.10 created keyring files with world-readable permissions. |
6Canonical DebianFedoraproject+3 more23Debian Linux Enterprise LinuxEnterprise Linux Desktop+20 moreJun 17, 2026 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI pro...Show more |
6Arista DebianFedoraproject+3 more11Cloudvision Portal Debian LinuxDeveloper Tools+8 moreJun 17, 2026 Oct 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that veri...Show more |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxJun 17, 2026 Oct 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol. |
2Debian Qt2Debian Linux QtbaseJun 17, 2026 Oct 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLoofah+1 moreJun 17, 2026 Oct 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished. |
5Debian FedoraprojectLibssh2+2 more10Active Iq Unified Manager Bootstrap OsDebian Linux+7 moreJun 17, 2026 Oct 21, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read...Show more |
6Canonical DebianFedoraproject+3 more6Active Iq Unified Manager Debian LinuxFedora+3 moreJun 17, 2026 Oct 21, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). |
3Canonical DebianXmlsoft3Debian Linux LibxsltUbuntu LinuxJun 17, 2026 Oct 18, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and me...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Element Software Management NodeEnterprise Linux+12 moreJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Oct 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider the interpretation of a name as a series of hex characters. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Oct 17, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow. |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreJun 17, 2026 Oct 16, 2019 N/A· v4 4.7 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attack...Show more |
6Canonical DebianNetapp+3 more19Debian Linux E Series Santricity Os ControllerE Series Santricity Storage Manager+16 moreJun 17, 2026 Oct 16, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulne...Show more |