CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Aug 13, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection faul...Show more |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Aug 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftImage function. It allows an attacker to cause a denial of service by sending a crafted file. |
3Debian FedoraprojectPdfresurrect Project3Debian Linux FedoraPdfresurrectJun 17, 2026 Aug 11, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write. |
7Apple CanonicalDebian+4 more7Debian Linux LeapMac Os X+4 moreJun 17, 2026 Aug 9, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data wh...Show more |
7Apple CanonicalDebian+4 more7Debian Linux LeapMac Os X+4 moreJun 17, 2026 Aug 9, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data wh...Show more |
4Canonical DebianOpenstack+1 more4Debian Linux NovaOpenstack+1 moreJun 17, 2026 Aug 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Aug 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and...Show more |
6Canonical DebianFedoraproject+3 more8Backports Sle Debian LinuxEnterprise Linux Desktop+5 moreJun 17, 2026 Aug 7, 2019 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .dir...Show more |
2Debian Thekelleys2Debian Linux DnsmasqJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability tha...Show more |
3Canonical DebianMilkytracker Project3Debian Linux MilkytrackerUbuntu LinuxJun 17, 2026 Aug 1, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow. |
3Canonical DebianMilkytracker Project3Debian Linux MilkytrackerUbuntu LinuxJun 17, 2026 Aug 1, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow. |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. |
2Debian Opencv2Debian Linux OpencvJun 17, 2026 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp. |
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter....Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraMilkytracker+1 moreJun 17, 2026 Jul 31, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow. |
3Debian FedoraprojectLibmodbus3Debian Linux FedoraLibmodbusJun 17, 2026 Jul 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301. |
3Debian FedoraprojectLibmodbus3Debian Linux FedoraLibmodbusJun 17, 2026 Jul 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302. |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapJun 17, 2026 Jul 31, 2019 N/A· v4 8.6 HIGH· v3 6.4 MEDIUM· v2 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This coul...Show more |
3Debian Icedtea Web ProjectOpensuse3Debian Linux Icedtea WebLeapJun 17, 2026 Jul 31, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a tr...Show more |
3Debian FedoraprojectNfdump Project3Debian Linux FedoraNfdumpJun 17, 2026 Jul 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service). |