Vulnerabilities > Canonical > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-01 CVE-2018-3979 Resource Exhaustion vulnerability in multiple products
A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution.
network
low complexity
canonical nvidia CWE-400
6.5
2019-03-30 CVE-2019-10649 Memory Leak vulnerability in multiple products
In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.
local
low complexity
imagemagick debian canonical CWE-401
5.5
2019-03-27 CVE-2019-3877 Open Redirect vulnerability in multiple products
A vulnerability was found in mod_auth_mellon before v0.14.2.
6.1
2019-03-27 CVE-2019-3821 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.
network
low complexity
ceph canonical CWE-772
5.0
2019-03-27 CVE-2019-3814 Improper Certificate Validation vulnerability in multiple products
It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates.
network
high complexity
dovecot canonical opensuse CWE-295
6.8
2019-03-27 CVE-2019-9917 Improper Input Validation vulnerability in multiple products
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
network
low complexity
znc canonical fedoraproject CWE-20
6.5
2019-03-25 CVE-2019-3874 Resource Exhaustion vulnerability in multiple products
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem.
6.5
2019-03-25 CVE-2019-10018 Divide By Zero vulnerability in multiple products
An issue was discovered in Xpdf 4.01.01.
local
low complexity
xpdfreader debian canonical CWE-369
5.5
2019-03-21 CVE-2019-9903 Out-of-bounds Write vulnerability in multiple products
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
6.5
2019-03-21 CVE-2019-7222 The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. 5.5