CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called. |
2Fedoraproject Khanacademy2Fedora Simple MarkdownJun 17, 2026 Apr 9, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI. |
2Fedoraproject Freedesktop2Fedora PopplerJun 17, 2026 Apr 8, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc. |
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |
8Apache CanonicalDebian+5 more14Clustered Data Ontap Debian LinuxEnterprise Linux+11 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing config...Show more |
2Apache Fedoraproject2Fedora Http ServerJun 17, 2026 Apr 8, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions. |
3Fedoraproject OpensuseRoundcube4Backports Sle FedoraLeap+1 moreJun 17, 2026 Apr 7, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or A...Show more |
5Canonical FedoraprojectOpensuse+2 more5Fedora JinjaLeap+2 moreJun 17, 2026 Apr 7, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. |
3Fedoraproject OpensuseRedhat3Fedora LeapLibvirtJun 17, 2026 Apr 4, 2019 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information...Show more |
3Fedoraproject GnuOpensuse3Fedora GnutlsLeapJun 17, 2026 Apr 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages. |
4Fedoraproject OpensuseRedhat+1 more8Edk Ii Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access. |
2Eclipse Fedoraproject2Fedora JettyNov 21, 2024 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames....Show more |
2Fedoraproject Gnu2Fedora GnutlsJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates...Show more |
3Debian FedoraprojectRubyonrails3Debian Linux FedoraRailsJun 17, 2026 Mar 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combinatio...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unre...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesyste...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more4Enterprise Linux FedoraMod Auth Mellon+1 moreJun 17, 2026 Mar 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert...Show more |
3Canonical FedoraprojectZnc3Fedora Ubuntu LinuxZncJun 17, 2026 Mar 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding. |
3Debian DrupalFedoraproject3Debian Linux DrupalFedoraJun 17, 2026 Mar 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger...Show more |