CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreNov 21, 2024 Mar 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In ImageMagick before 7.0.8-25, some memory leaks exist in DecodeImage in coders/pcd.c. |
5Debian FedoraprojectLibjpeg Turbo+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Mar 7, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or...Show more |
5Canonical DebianLinux+2 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Mar 5, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers to exploit kernel NULL pointer dereferences on non-SMAP platforms. This is...Show more |
3Debian Live555Opensuse4Backports Sle Debian LinuxLeap+1 moreNov 21, 2024 Feb 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapUbuntu Linux+1 moreNov 21, 2024 Feb 28, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in ti...Show more |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreNov 21, 2024 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
3Canonical OpensuseWebkitgtk3Leap Ubuntu LinuxWebkitgtkNov 21, 2024 Feb 24, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote atta...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreNov 21, 2024 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XMLRPC server to cause PHP to read memory outside of allocated areas in ba...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreNov 21, 2024 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when su...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreNov 21, 2024 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read al...Show more |
5Canonical DebianNetapp+2 more5Debian Linux LeapPhp+2 moreNov 21, 2024 Feb 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or...Show more |
4Canonical LinuxNetapp+1 more7Cn1610 Firmware Hci Management NodeLeap+4 moreNov 21, 2024 Feb 22, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd re...Show more |
In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreNov 21, 2024 Feb 21, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures. |
5Debian OpensuseOracle+2 more9Backports Sle Communications Operations MonitorDebian Linux+6 moreNov 21, 2024 Feb 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapQemu+1 moreNov 21, 2024 Feb 19, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could e...Show more |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreNov 21, 2024 Feb 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr. |
4Canonical DebianFile Project+1 more4Debian Linux FileLeap+1 moreNov 21, 2024 Feb 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact. |
4Apple CanonicalFile Project+1 more7File Iphone OsLeap+4 moreNov 21, 2024 Feb 18, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. |
4Canonical DebianFile Project+1 more4Debian Linux FileLeap+1 moreNov 21, 2024 Feb 18, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. |