CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreNov 21, 2024 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data wh...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreNov 21, 2024 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to informa...Show more |
8Canonical DebianFedoraproject+5 more13Debian Linux Enterprise LinuxFedora+10 moreNov 21, 2024 Jun 19, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to...Show more |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsNov 21, 2024 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence inj...Show more |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsNov 21, 2024 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occ...Show more |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsNov 21, 2024 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible. |
3Debian OpensuseRubygems3Debian Linux LeapRubygemsNov 21, 2024 Jun 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.) |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxLeap+1 moreNov 21, 2024 Jun 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eva...Show more |
6Canonical DebianLinux+3 more23A700s Firmware Active Iq Unified ManagerCn1610 Firmware+20 moreNov 21, 2024 Jun 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences. |
6Apache CanonicalFedoraproject+3 more11Communications Session Report Manager Communications Session Route ManagerEnterprise Manager Ops Center+8 moreNov 21, 2024 Jun 11, 2019 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the fir...Show more |
5Apache CanonicalDebian+2 more5Debian Linux FedoraHttp Server+2 moreNov 21, 2024 Jun 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for dup...Show more |
7Canonical DebianFedoraproject+4 more14Cloud Backup Converged Systems Advisor AgentDebian Linux+11 moreNov 21, 2024 Jun 7, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attack...Show more |
5Canonical FedoraprojectLinux+2 more5Enterprise Linux FedoraLeap+2 moreNov 21, 2024 Jun 3, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial...Show more |
7Canonical DebianFedoraproject+4 more12A700s Firmware Active Iq Unified Manager For Vmware VsphereCn1610 Firmware+9 moreNov 21, 2024 Jun 3, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network. |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapSqlite+1 moreNov 21, 2024 May 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables. |
6Canonical DebianFedoraproject+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreNov 21, 2024 May 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. |
4Canonical FedoraprojectGnome+1 more4Fedora GvfsLeap+1 moreNov 21, 2024 May 29, 2019 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file://...Show more |
4Canonical FedoraprojectGnome+1 more4Fedora GvfsLeap+1 moreNov 21, 2024 May 29, 2019 N/A· v4 7.3 HIGH· v3 4.9 MEDIUM· v2 An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used. |
7Debian F5Fedoraproject+4 more11Debian Linux Enterprise Manager Ops CenterFedora+8 moreApr 15, 2026 May 28, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
2Google Opensuse3Backports ChromeLeapNov 21, 2024 May 23, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform domain spoofing via a crafted domain name. |