CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianSpip3Debian Linux SpipUbuntu LinuxJun 17, 2026 Sep 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_actio...Show more |
8Canonical DebianFedoraproject+5 more34Aff A700s Firmware Data Availability ServicesDebian Linux+31 moreJun 17, 2026 Sep 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpendmarc+1 moreJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin o...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes. |
6Debian FedoraprojectHaxx+3 more17Cloud Backup Communications Operations MonitorCommunications Session Border Controller+14 moreJun 17, 2026 Sep 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. |
6Debian FedoraprojectHaxx+3 more12Cloud Backup Communications Operations MonitorCommunications Session Border Controller+9 moreJun 17, 2026 Sep 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. |
2Debian Gpac2Debian Linux GpacNov 21, 2024 Sep 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. |
2Debian Gpac2Debian Linux GpacNov 21, 2024 Sep 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 AVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. There is "cfg_new->AVCLevelIndication =...Show more |
6Debian FasterxmlFedoraproject+3 more17Banking Platform Customer Management And Segmentation FoundationDebian Linux+14 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. |
6Debian FasterxmlFedoraproject+3 more19Banking Platform Customer Management And Segmentation FoundationDebian Linux+16 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. |
3Debian OpensuseWireshark3Debian Linux LeapWiresharkJun 17, 2026 Sep 15, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero. |
3Canonical DebianW1.fi4Debian Linux HostapdUbuntu Linux+1 moreJun 17, 2026 Sep 12, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been p...Show more |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. |
4Canonical DebianDino+1 more4Debian Linux DinoFedora+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 WordPress before 5.2.3 allows XSS in post previews by authenticated users. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows reflected XSS in the dashboard. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash. |
2Debian Wordpress2Debian Linux WordpressJun 17, 2026 Sep 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 WordPress before 5.2.3 allows XSS in shortcode previews. |