CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLibsndfile Project3Debian Linux LibsndfileUbuntu LinuxJun 17, 2026 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the app...Show more |
2Debian Yubico2Debian Linux Libu2f HostNov 21, 2024 Mar 21, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device...Show more |
3Debian LinuxNetapp4Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read...Show more |
4Bestpractical CanonicalDebian+1 more4Debian Linux FedoraRequest Tracker+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing. |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpa...Show more |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database acce...Show more |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution. |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code exe...Show more |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code ex...Show more |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault). |
3Debian OpensuseRdesktop4Backports Debian LinuxLeap+1 moreNov 21, 2024 Mar 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code executi...Show more |
2Debian Rdesktop2Debian Linux RdesktopNov 21, 2024 Mar 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault). |
3Debian Gpsd ProjectMicrojson Project3Debian Linux GpsdMicrojsonNov 21, 2024 Mar 13, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on P...Show more |
4Debian FedoraprojectGolang+1 more5Debian Linux Developer ToolsEnterprise Linux+2 moreJun 17, 2026 Mar 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a R...Show more |
3Debian OpenstackRedhat3Debian Linux NeutronOpenstackJun 17, 2026 Mar 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along wit...Show more |
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxJun 17, 2026 Mar 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex for...Show more |
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error. |
3Cron Project DebianFedoraproject3Cron Debian LinuxFedoraJun 17, 2026 Mar 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted. |
3Cron Project DebianFedoraproject3Cron Debian LinuxFedoraJun 17, 2026 Mar 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked. |
3Checkstyle DebianFedoraproject3Checkstyle Debian LinuxFedoraJun 17, 2026 Mar 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Checkstyle before 8.18 loads external DTDs by default. |