Vulnerabilities > Canonical > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-07-09 CVE-2019-13454 Divide By Zero vulnerability in multiple products
ImageMagick 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
network
low complexity
imagemagick debian canonical opensuse CWE-369
6.5
2019-07-05 CVE-2019-13311 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error.
network
low complexity
imagemagick canonical debian opensuse CWE-401
6.5
2019-07-05 CVE-2019-13310 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c.
network
low complexity
imagemagick canonical opensuse CWE-401
6.5
2019-07-05 CVE-2019-13309 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIListOperatorImages in MagickWand/operation.c.
network
low complexity
imagemagick debian canonical opensuse CWE-401
6.5
2019-07-05 CVE-2019-13301 Memory Leak vulnerability in multiple products
ImageMagick 7.0.8-50 Q16 has memory leaks in AcquireMagickMemory because of an AnnotateImage error.
network
low complexity
imagemagick debian canonical opensuse CWE-401
6.5
2019-07-01 CVE-2019-13137 Memory Leak vulnerability in multiple products
ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
network
low complexity
imagemagick debian canonical CWE-401
6.5
2019-07-01 CVE-2019-12781 Cleartext Transmission of Sensitive Information vulnerability in multiple products
An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3.
network
low complexity
djangoproject canonical debian CWE-319
5.3
2019-07-01 CVE-2019-13118 Type Confusion vulnerability in multiple products
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data.
5.3
2019-07-01 CVE-2019-13117 Use of Uninitialized Resource vulnerability in multiple products
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers.
5.3
2019-06-30 CVE-2019-13114 NULL Pointer Dereference vulnerability in multiple products
http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character.
network
low complexity
exiv2 fedoraproject debian canonical CWE-476
6.5