VYPR

Ubuntu Linux

by Canonical

CVEs (4,123)

  • CVE-2019-10092MedSep 26, 2019
    risk 0.49cvss 6.1epss 0.81

    In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server…

  • CVE-2019-5094HigSep 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

  • CVE-2019-16095HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.

  • CVE-2019-16094HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.

  • CVE-2019-16091HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.

  • CVE-2019-15099HigAug 16, 2019
    risk 0.49cvss 7.5epss 0.04

    drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

  • CVE-2019-14494HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

  • CVE-2019-13565HigJul 26, 2019
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity…

  • CVE-2019-13619HigJul 17, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.

  • CVE-2019-10192HigJul 11, 2019
    risk 0.49cvss 7.2epss 0.26

    A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL…

  • CVE-2019-12295HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.04

    In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.

  • CVE-2019-12211HigMay 20, 2019
    risk 0.49cvss 7.5epss 0.04

    When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered, resulting in a heap overflow.

  • CVE-2019-2632HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple…

  • CVE-2019-2602HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2019-9628HigApr 11, 2019
    risk 0.49cvss 7.5epss 0.02

    The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and…

  • CVE-2019-10903HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.

  • CVE-2019-10901HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by handling file digests properly.

  • CVE-2019-10899HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by preventing a heap-based buffer under-read.

  • CVE-2019-10896HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.

  • CVE-2019-10895HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improving data validation.

Page 48 of 207