CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Upx2Fedora UpxJun 17, 2026 Dec 27, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service. |
2Fedoraproject Upx2Fedora UpxJun 17, 2026 Dec 27, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file. |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 26, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential fo...Show more |
7Canonical DebianFedoraproject+4 more12Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+9 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
4Debian FedoraprojectPhp+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowerc...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string cont...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti...Show more |
3Fedoraproject PhpTenable3Fedora PhpSecuritycenterJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabil...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a lin...Show more |
3Fedoraproject Lout ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. |
3Fedoraproject Lout ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. |
7Apache AppleCanonical+4 more19Bookkeeper Cyrus SaslDebian Linux+16 moreJun 17, 2026 Dec 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more |
3Fedoraproject OpensuseRack3Fedora LeapRackJun 17, 2026 Dec 18, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing att...Show more |
5Apache DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 4, 2025 Dec 18, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current m...Show more |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 6.5 MEDIUM· v3 7.5 HIGH· v2 ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests. |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request. |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the E...Show more |