CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectJhead Project3Debian Linux FedoraJheadJun 17, 2026 Jul 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file. |
3Debian FedoraprojectJhead Project3Debian Linux FedoraJheadJun 17, 2026 Jul 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibmspack+1 moreJun 17, 2026 Jul 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libmspack 0.9.1alpha is affected by: Buffer Overflow. The impact is: Information Disclosure. The component is: function chmd_read_headers() in libmspack(file libmspack/mspack/chmd.c). The attack vector is: the victim mus...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vecto...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 WavPack 5.1 and earlier is affected by: CWE 369: Divide by Zero. The impact is: Divide by zero can lead to sudden crash of a software/service that tries to parse a .wav file. The component is: ParseDsdiffHeaderConfig (ds...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 11, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode det...Show more |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Jul 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't g...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, u...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibzmq+1 moreJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled...Show more |
2Fedoraproject Oniguruma Project2Fedora OnigurumaJun 17, 2026 Jul 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as c...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOniguruma+2 moreJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression....Show more |
3Fedoraproject LibosinfoRedhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreJun 17, 2026 Jul 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. I...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftot...Show more |
2Deepin Fedoraproject2Deepin Clone FedoraJun 17, 2026 Jul 4, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare...Show more |
3Debian DosboxFedoraproject3Debian Linux DosboxFedoraJun 17, 2026 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code. |