CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Dec 27, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sig...Show more |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are...Show more |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_verror in asm/preproc.c that will cause a remote denial of service attack. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that will cause a remote denial of service attack. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum a...Show more |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111. |
2Canonical Nasm2Netwide Assembler Ubuntu LinuxMay 13, 2026 Dec 21, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments. |
6Canonical DebianLinux+3 more8Debian Linux LeapLeap+5 moreMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interfa...Show more |
6Canonical DebianLinux+3 more8Debian Linux LeapLeap+5 moreMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER)...Show more |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c. |
3Canonical DebianGimp3Debian Linux GimpUbuntu LinuxMay 13, 2026 Dec 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data. |