CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxJun 17, 2026 Feb 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. A NULL pointer dereference occurs for an "empty" nick. |
3Canonical OpensuseSystemd Project3Leap SystemdUbuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a fil...Show more |
2Canonical Gnu2Patch Ubuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rena...Show more |
2Canonical Freetype2Freetype Ubuntu LinuxJun 17, 2026 Feb 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in FreeType 2 through 2.9. A NULL pointer dereference in the Ins_GETVARIATION() function within ttinterp.c could lead to DoS via a crafted font file. |
4Canonical DebianLinux+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Feb 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wak...Show more |
3Canonical DebianSquid Cache3Debian Linux SquidUbuntu LinuxNov 21, 2024 Feb 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Ser...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes car...Show more |
3Canonical DebianSquid Cache3Debian Linux SquidUbuntu LinuxNov 21, 2024 Feb 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clie...Show more |
3Canonical PuppetRedhat4Puppet Puppet EnterpriseSatellite+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability. |
4Canonical DebianPostgresql+1 more4Cloudforms Debian LinuxPostgresql+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.0 HIGH· v3 3.3 LOW· v2 In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under um...Show more |
4Canonical DebianLibreoffice+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreJun 17, 2026 Feb 9, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function. |
3Canonical DebianGdraheim3Debian Linux Ubuntu LinuxZziplibJun 17, 2026 Feb 9, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a...Show more |
In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be controlled if the input can be controlled (e.g., during file uploads). For example, a "$uri = strea...Show more |
3Canonical DebianExim3Debian Linux EximUbuntu LinuxJun 17, 2026 Feb 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely. |
2Canonical Python2Python Ubuntu LinuxNov 21, 2024 Feb 8, 2018 N/A· v4 3.6 LOW· v3 3.3 LOW· v2 Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however th...Show more |
3Canonical DebianWavpack3Debian Linux Ubuntu LinuxWavpackJun 17, 2026 Feb 6, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a malici...Show more |
2Canonical Djangoproject2Django Ubuntu LinuxJun 17, 2026 Feb 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allow...Show more |
4Canonical DebianOracle+1 more4Debian Linux GeorasterOpenjpeg+1 moreJun 17, 2026 Feb 4, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. |
3Canonical DebianDlitz3Debian Linux PycryptoUbuntu LinuxJun 17, 2026 Feb 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxNov 3, 2025 Feb 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resour...Show more |