Vulnerabilities > Canonical > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-27 CVE-2019-9325 Out-of-bounds Read vulnerability in multiple products
In libvpx, there is a possible out of bounds read due to a missing bounds check.
6.5
2019-09-26 CVE-2019-10092 Cross-site Scripting vulnerability in multiple products
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page.
6.1
2019-09-25 CVE-2017-18635 Cross-site Scripting vulnerability in multiple products
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
network
low complexity
novnc debian canonical redhat CWE-79
6.1
2019-09-25 CVE-2019-13627 Information Exposure Through Discrepancy vulnerability in multiple products
It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library.
6.3
2019-09-24 CVE-2019-5094 Out-of-bounds Write vulnerability in multiple products
An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3.
6.7
2019-09-23 CVE-2019-16713 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
network
low complexity
imagemagick canonical opensuse debian CWE-401
6.5
2019-09-23 CVE-2019-16711 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
network
low complexity
imagemagick debian opensuse canonical CWE-401
6.5
2019-09-23 CVE-2019-16710 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
network
low complexity
imagemagick debian opensuse canonical CWE-401
6.5
2019-09-23 CVE-2019-16709 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
network
low complexity
imagemagick opensuse canonical CWE-401
6.5
2019-09-23 CVE-2019-16708 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
network
low complexity
imagemagick canonical opensuse debian CWE-401
6.5