Canonical
canonical
4,238 CVEs • 60 products
Products (60)
Click to collapseToggle
Products (60)
Click to collapse
CVEs (4,238)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jul 5, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jul 5, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jul 5, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled. |
2Canonical Flightcrew Project2Flightcrew Ubuntu LinuxJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. |
4Canonical DebianLibsdl+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to...Show more |
4Canonical DebianLibsdl+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jul 3, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can pro...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 Jul 3, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a --br=bridge option) is limited to the IFNAMSIZ size, which can lead to an ACL bypass. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxJun 17, 2026 Jul 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c. |
4Canonical DebianF5+1 more5Big Ip Application Acceleration Manager Big Ip WebacceleratorDebian Linux+2 moreJun 17, 2026 Jul 1, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c. |
3Canonical DebianDjangoproject3Debian Linux DjangoUbuntu LinuxJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not redirected to HTTPS when the SECURE_PROXY_SSL_HEADER and SECURE_SSL_REDIRECT settings are used, and t...Show more |
7Apple CanonicalFedoraproject+4 more25Active Iq Unified Manager Cloud BackupClustered Data Ontap+22 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...Show more |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. |
3Canonical Exiv2Fedoraproject3Exiv2 FedoraUbuntu LinuxJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file. |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file. |
4Canonical FedoraprojectMod Auth Mellon Project+1 more4Fedora Mod Auth MellonUbuntu Linux+1 moreJun 17, 2026 Jun 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. |
5Canonical DebianFedoraproject+2 more6Backports ChromeDebian Linux+3 moreJun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Canonical Google2Chrome Ubuntu LinuxJun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. |
4Canonical DebianImagemagick+1 more4Debian Linux ImagemagickLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c. |