CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Aug 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file. |
3Canonical FedoraprojectGnu3Fedora PatchUbuntu LinuxMay 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a di...Show more |
Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9...Show more |
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubu...Show more |
4Canonical FedoraprojectGnu+1 more4Fedora MageiaPatch+1 moreMay 13, 2026 Aug 25, 2017 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file. |
3Canonical DebianGnu3Cvs Debian LinuxUbuntu LinuxMay 13, 2026 Aug 24, 2017 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar." |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Aug 23, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Aug 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk. |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the...Show more |
6Apache CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 13, 2026 Aug 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to thos...Show more |
6Apache CanonicalDebian+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreMay 13, 2026 Aug 10, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 t...Show more |
6Apache CanonicalDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that...Show more |
6Apache CanonicalDebian+3 more15Communications Diameter Signaling Router Debian LinuxEnterprise Linux Desktop+12 moreMay 13, 2026 Aug 10, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not e...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 13, 2026 Aug 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tre...Show more |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxMay 13, 2026 Aug 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink. |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Jul 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input. |
2Canonical Oxide Project2Oxide Ubuntu LinuxMay 13, 2026 Jul 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a c...Show more |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 13, 2026 Jul 25, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Jul 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input. |
7Canonical DebianFedoraproject+4 more20Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+17 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more |