CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libsdl Opensuse3Backports Sle LeapSdl2 ImageJun 17, 2026 Jul 31, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer...Show more |
2Libsdl Opensuse3Backports Sle LeapSdl2 ImageJun 17, 2026 Jul 31, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can displ...Show more |
2Libsdl Opensuse3Backports Sle LeapSdl2 ImageJun 17, 2026 Jul 31, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can displ...Show more |
2Opensuse Videolan4Backports Backports SleLeap+1 moreJun 17, 2026 Jul 30, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. |
2Mcpp Project Opensuse3Backports Sle LeapMcppJun 17, 2026 Jul 26, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. |
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. |
6Canonical DebianFedoraproject+3 more13Backports Sle Debian LinuxEnterprise Linux+10 moreJun 17, 2026 Jul 16, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c. |
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 14, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly...Show more |
4Canonical DebianLibsdl+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to...Show more |
4Canonical DebianLibsdl+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can pro...Show more |
2Google Opensuse3Backports Sle ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
2Google Opensuse3Backports Sle ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Google Opensuse3Backports Sle ChromeLeapJun 17, 2026 May 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
5Canonical DebianFedoraproject+2 more7Backports Sle Debian LinuxFedora+4 moreJun 17, 2026 May 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c. |
4Debian FedoraprojectHeimdal Project+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 May 15, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly...Show more |
4Canonical DebianGraphicsmagick+1 more5Backports Sle Debian LinuxGraphicsmagick+2 moreJun 17, 2026 Apr 24, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly hav...Show more |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Apr 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-20...Show more |
11Backdropcms DebianDrupal+8 more105Agile Product Lifecycle Management For Process Application ExpressApplication Service Level Management+102 moreJun 17, 2026 Apr 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacke...Show more |