Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2019-2054
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. T…
Ubuntu Linux
No fix yet
HIGH 7.5
CVE-2019-11596
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when …
Ubuntu Linux
1.5.14+
HIGH 7.8
CVE-2019-3844
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would al…
Ubuntu Linux
242+
HIGH 7.5
CVE-2019-11502
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, tha…
Snapd
2.38+
HIGH 7.5
CVE-2019-11503
snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the…
Snapd
2.39+
MEDIUM 6.5
CVE-2019-11498
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" co…
Ubuntu Linux
after 5.1.0
HIGH 8.1
CVE-2019-2697EPSS 11%
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Diffi…
Ubuntu Linux
Patch available
CRITICAL 9.8
CVE-2019-7304EPSS 63%
Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitrary commands as root. This iss…
Snapd
2.37.1+
HIGH 7.5
CVE-2019-7303
A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 6…
Snapd
2.37.4+
MEDIUM 5.5
CVE-2019-11459
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle err…
Ubuntu Linux
after 3.32.0
CRITICAL 9.8
CVE-2016-1579
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functiona…
Ubuntu Download Manager
Mitigation only
CRITICAL 9.8
CVE-2016-1585
In all versions of AppArmor mount rules are accidentally widened when compiled.
Apparmor
2.13.10 / 3.0.12+
MEDIUM 6.1
CVE-2019-11454
Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbit…
Ubuntu Linux
5.25.3+
CRITICAL 9.8
CVE-2015-1320
The SeaMicro provisioning of Ubuntu MAAS logs credentials, including username and password, for the management interface. This issue affects Ubuntu M…
Metal As A Service
1.9.2+
HIGH 7.8
CVE-2015-1341
Any Python module in sys.path can be imported if the command line of the process triggering the coredump is Python and the first argument is -m in Ap…
Ubuntu Linux
2.19.2+
HIGH 7.5
CVE-2014-1426
A vulnerability in maasserver.api.get_file_by_name of Ubuntu MAAS allows unauthenticated network clients to download any file. This issue affects: Ub…
Metal As A Service
1.9.2+
HIGH 7.5
CVE-2015-1316
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
Juju
1.25.5+
MEDIUM 6.1
CVE-2014-1427
A vulnerability in the REST API of Ubuntu MAAS allows an attacker to cause a logged-in user to execute commands via cross-site scripting. This issue …
Metal As A Service
1.9.2+
MEDIUM 5.9
CVE-2011-3151
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have sym…
Selinux
1+
MEDIUM 5.3
CVE-2014-1428
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior…
Metal As A Service
1.9.2+
HIGH 7.5
CVE-2019-3885
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via t…
Ubuntu Linux
after 2.0.1
HIGH 7.8
CVE-2018-16877
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could us…
Ubuntu Linux
after 2.0.0
MEDIUM 5.5
CVE-2018-16878
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead…
Ubuntu Linux
after 2.0.1
HIGH 7.5
CVE-2019-9628
The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing cla…
Ubuntu Linux
3.0.4+
CRITICAL 9.8
CVE-2019-11068EPSS 5%
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving …
Ubuntu Linux
after 1.1.33
MEDIUM 6.5
CVE-2018-3979
A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader e…
Ubuntu Linux
No fix yet
CRITICAL 9.8
CVE-2019-10269
BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name…
Ubuntu Linux
2019-01-23+
HIGH 7.5
CVE-2019-3821
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create mu…
Ubuntu Linux
1.11+
MEDIUM 6.8
CVE-2019-3814
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote attacker in possession of a val…
Ubuntu Linux
2.2.36.1 / 2.3.4.1+
MEDIUM 6.5
CVE-2019-9917
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
Ubuntu Linux
after 1.7.2