CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical NetappNtp3Element Software NtpUbuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mode 6 packet with a ntpd instance from 4.2.8p6 through 4.2.8p10. |
2Canonical Exempi Project2Exempi Ubuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, leading to a NULL pointer dereference in the WEBP::VP8XChunk class. |
3Canonical DebianExempi Project3Debian Linux ExempiUbuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter.cpp, leading to a heap-based buffer over-read in the PSD_MetaHandler::...Show more |
2Canonical Exempi Project2Exempi Ubuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exempi through 2.4.4. There is a stack-based buffer over-read in the PostScript_MetaHandler::ParsePSFile() function in XMPFiles/source/FileHandlers/PostScript_Handler.cpp. |
3Canonical DebianExempi Project3Debian Linux ExempiUbuntu LinuxJun 17, 2026 Mar 6, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FileHandlers/TIFF_Handler.cpp mishandles a case of a zero length, leading to a heap-based buffer over-read in the MD5Update() function in third-party/zuid/...Show more |
3Canonical GdraheimRedhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Mar 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a denial of service via a crafted zip fil...Show more |
3Canonical GdraheimRedhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Mar 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service. |
2Canonical Gpac Project2Gpac Ubuntu LinuxNov 21, 2024 Mar 6, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be...Show more |
4Canonical DebianMemcached+1 more4Debian Linux MemcachedOpenstack+1 moreNov 21, 2024 Mar 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via networ...Show more |
3Canonical PostgresqlRedhat3Cloudforms PostgresqlUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the databa...Show more |
3Canonical DebianDovecot3Debian Linux DovecotUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server...Show more |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Mar 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel. |
2Canonical Imagemagick2Imagemagick Ubuntu LinuxNov 21, 2024 Mar 1, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory...Show more |
3Canonical DebianPhp3Debian Linux PhpUbuntu LinuxJun 17, 2026 Mar 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standa...Show more |
4Canonical DebianQemu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Mar 1, 2018 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which trig...Show more |
5Apache CanonicalDebian+2 more10Debian Linux Fusion MiddlewareHospitality Guest Access+7 moreNov 21, 2024 Feb 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of...Show more |
3Canonical RedhatZsh5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Feb 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p. |
2Canonical Zsh2Ubuntu Linux ZshJun 17, 2026 Feb 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result. |
2Canonical Zsh2Ubuntu Linux ZshNov 21, 2024 Feb 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In utils.c in zsh before 5.4, symlink expansion had a buffer overflow. |