CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
10Apache CanonicalDebian+7 more19Debian Linux Enterprise LinuxEnterprise Linux Eus+16 moreJun 17, 2026 Jan 31, 2019 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validati...Show more |
9Canonical DebianFedoraproject+6 more20Debian Linux Element SoftwareEnterprise Linux+17 moreJun 17, 2026 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g.,...Show more |
7Apache CanonicalDebian+4 more12Debian Linux Enterprise Manager Ops CenterFedora+9 moreNov 21, 2024 Jan 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. Thi...Show more |
2Fedoraproject Numpy2Fedora NumpyJun 17, 2026 Jan 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NO...Show more |
2Fedoraproject Juniper2Fedora JunosJun 17, 2026 Jan 15, 2019 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and...Show more |
4Debian FedoraprojectOpensuse+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 15, 2019 N/A· v4 5.2 MEDIUM· v3 2.7 LOW· v2 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that res...Show more |
3Etcd FedoraprojectRedhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Jan 14, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS cer...Show more |
6Canonical FedoraprojectGnome+3 more6Epiphany FedoraLeap+3 moreJun 17, 2026 Jan 14, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is...Show more |
4Canonical DebianDjangoproject+1 more4Debian Linux DjangoFedora+1 moreJun 17, 2026 Jan 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found()...Show more |
5Canonical DebianFedoraproject+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Jan 3, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in whi...Show more |
4Aria2 Project CanonicalDebian+1 more4Aria2 Debian LinuxFedora+1 moreJun 17, 2026 Jan 2, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file. |
2Fedoraproject Msweet2Fedora Mini XmlNov 21, 2024 Dec 30, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Mini-XML (aka mxml) v2.12, there is stack-based buffer overflow in the scan_file function in mxmldoc.c. |
2Fedoraproject Msweet2Fedora Mini XmlNov 21, 2024 Dec 30, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstr...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19. |
4Canonical FedoraprojectLibcaca Project+1 more4Fedora LeapLibcaca+1 moreNov 21, 2024 Dec 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 28, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Dec 28, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case. |
4Canonical FedoraprojectLibcaca Project+1 more4Fedora LeapLibcaca+1 moreNov 21, 2024 Dec 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data. |
3Debian FedoraprojectPython3Debian Linux FedoraPythonNov 21, 2024 Dec 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevan...Show more |
3Canonical FedoraprojectQemu3Fedora QemuUbuntu LinuxNov 21, 2024 Dec 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference). |