Ubuntu Linux
by Canonical
CVEs (4,123)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16866 | Hig | 0.42 | 7.5 | 0.04 | Oct 3, 2019 | Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule. | ||
| CVE-2019-9433 | Med | 0.42 | 6.5 | 0.03 | Sep 27, 2019 | In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:… | ||
| CVE-2019-9371 | Med | 0.42 | 6.5 | 0.03 | Sep 27, 2019 | In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:… | ||
| CVE-2019-9325 | Med | 0.42 | 6.5 | 0.03 | Sep 27, 2019 | In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:… | ||
| CVE-2019-16869 | Hig | 0.42 | 7.5 | 0.08 | Sep 26, 2019 | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling. | ||
| CVE-2019-16884 | Hig | 0.42 | 7.5 | 0.04 | Sep 25, 2019 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. | ||
| CVE-2019-16714 | Hig | 0.42 | 7.5 | 0.03 | Sep 23, 2019 | In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized. | ||
| CVE-2019-16713 | Med | 0.42 | 6.5 | 0.02 | Sep 23, 2019 | ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c. | ||
| CVE-2019-16711 | Med | 0.42 | 6.5 | 0.02 | Sep 23, 2019 | ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c. | ||
| CVE-2019-16710 | Med | 0.42 | 6.5 | 0.02 | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c. | ||
| CVE-2019-16709 | Med | 0.42 | 6.5 | 0.03 | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. | ||
| CVE-2019-16708 | Med | 0.42 | 6.5 | 0.02 | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage. | ||
| CVE-2019-16391 | Med | 0.42 | 6.5 | 0.01 | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php. | ||
| CVE-2019-16275 | Med | 0.42 | 6.5 | 0.01 | Sep 12, 2019 | hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The… | ||
| CVE-2019-16237 | Hig | 0.42 | 7.5 | 0.01 | Sep 11, 2019 | Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. | ||
| CVE-2019-16236 | Hig | 0.42 | 7.5 | 0.02 | Sep 11, 2019 | Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. | ||
| CVE-2019-16235 | Hig | 0.42 | 7.5 | 0.01 | Sep 11, 2019 | Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala. | ||
| CVE-2019-16163 | Hig | 0.42 | 7.5 | 0.03 | Sep 9, 2019 | Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. | ||
| CVE-2015-9383 | Med | 0.42 | 6.5 | 0.02 | Sep 3, 2019 | FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c. | ||
| CVE-2019-11476 | Med | 0.42 | 6.5 | 0.01 | Aug 29, 2019 | An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the… |
- risk 0.42cvss 7.5epss 0.04
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
- risk 0.42cvss 6.5epss 0.03
In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…
- risk 0.42cvss 6.5epss 0.03
In libvpx, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…
- risk 0.42cvss 6.5epss 0.03
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID:…
- risk 0.42cvss 7.5epss 0.08
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.
- risk 0.42cvss 7.5epss 0.04
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
- risk 0.42cvss 7.5epss 0.03
In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized.
- risk 0.42cvss 6.5epss 0.02
ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
- risk 0.42cvss 6.5epss 0.02
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
- risk 0.42cvss 6.5epss 0.02
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
- risk 0.42cvss 6.5epss 0.03
ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
- risk 0.42cvss 6.5epss 0.02
ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
- risk 0.42cvss 6.5epss 0.01
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
- risk 0.42cvss 6.5epss 0.01
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The…
- risk 0.42cvss 7.5epss 0.01
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
- risk 0.42cvss 7.5epss 0.02
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
- risk 0.42cvss 7.5epss 0.01
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
- risk 0.42cvss 7.5epss 0.03
Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
- risk 0.42cvss 6.5epss 0.02
FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.
- risk 0.42cvss 6.5epss 0.01
An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in an out-of-bounds write to a heap allocated buffer when processing large crash dumps. This results in a crash or possible code-execution in the context of the…
Page 71 of 207