Vulnerabilities > Canonical > Ubuntu Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2018-5109 Origin Validation Error vulnerability in multiple products
An audio capture session can started under an incorrect origin from the site making the capture request.
network
low complexity
mozilla canonical CWE-346
5.3
2018-06-11 CVE-2018-5108 Information Exposure vulnerability in multiple products
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab.
network
low complexity
mozilla canonical CWE-200
4.3
2018-06-11 CVE-2018-5107 Link Following vulnerability in multiple products
The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions.
network
low complexity
mozilla canonical CWE-59
5.3
2018-06-11 CVE-2018-5106 Information Exposure vulnerability in multiple products
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open.
network
low complexity
mozilla canonical CWE-200
5.3
2018-06-11 CVE-2017-7829 Improper Input Validation vulnerability in multiple products
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient.
network
low complexity
mozilla redhat debian canonical CWE-20
5.3
2018-06-11 CVE-2018-10360 Out-of-bounds Read vulnerability in multiple products
The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.
network
low complexity
file-project canonical opensuse CWE-125
6.5
2018-06-08 CVE-2018-4232 An issue was discovered in certain Apple products.
network
low complexity
apple canonical
4.3
2018-06-01 CVE-2018-11656 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-06-01 CVE-2018-11655 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-05-31 CVE-2018-5388 Out-of-bounds Write vulnerability in multiple products
In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.
network
low complexity
strongswan debian canonical CWE-787
6.5