CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianFile3\ Debian LinuxUbuntu LinuxMay 13, 2026 Jun 1, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic. |
2Canonical Exiv22Exiv2 Ubuntu LinuxMay 13, 2026 May 26, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of p...Show more |
2Canonical Qpdf Project2Qpdf Ubuntu LinuxMay 13, 2026 May 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3. |
2Canonical Qpdf Project2Qpdf Ubuntu LinuxMay 13, 2026 May 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2. |
2Canonical Qpdf Project2Qpdf Ubuntu LinuxMay 13, 2026 May 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1. |
10Apple CanonicalDebian+7 more24Active Iq Unified Manager Database ServerDebian Linux+21 moreMay 13, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. |
8Apple CanonicalDebian+5 more19Database Server Debian LinuxEnterprise Linux Desktop+16 moreJul 14, 2026 May 23, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. |
9Apple CanonicalDebian+6 more39Active Iq Unified Manager Cloud BackupDatabase Server+36 moreJul 14, 2026 May 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
9Apple BoostCanonical+6 more20Boost Database ServerDebian Linux+17 moreJul 14, 2026 May 23, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. |
2Canonical Libtiff2Libtiff Ubuntu LinuxMay 13, 2026 May 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer o...Show more |
2Canonical Ytnef Project2Ubuntu Linux YtnefMay 13, 2026 May 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 May 8, 2017 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other i...Show more |
2Avahi Canonical2Avahi Ubuntu LinuxMay 13, 2026 May 1, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) a...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Apr 18, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a denial of service (system crash) via a long RPC reply, related to net/sunrpc/svc.c, fs/nfsd/nfs3xdr.c, a...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Apr 17, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and by...Show more |
3Canonical Nettle ProjectRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 13, 2026 Apr 14, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. |
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 1...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraLeap+7 moreMay 13, 2026 Apr 13, 2017 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). |
2Canonical Openstack2Nova Lxd Ubuntu LinuxMay 13, 2026 Apr 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. |