CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
6Apache CanonicalDebian+3 more197 Mode Transition Tool Agile Engineering Data ManagementAgile Plm+16 moreApr 21, 2026 Apr 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p...Show more |
2Canonical Lightdm Project2Lightdm Ubuntu LinuxMay 13, 2026 Apr 5, 2017 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out. |
2Canonical Debian2Debian Linux Ubuntu LinuxMay 13, 2026 Mar 28, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended...Show more |
3Canonical Cryptography.ioFedoraproject3Cryptography FedoraUbuntu LinuxMay 13, 2026 Mar 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. |
2Canonical Jasper Project2Jasper Ubuntu LinuxMay 13, 2026 Mar 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Mar 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access. |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 13, 2026 Mar 23, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 packa...Show more |
3Apache CanonicalDebian3Debian Linux TomcatUbuntu LinuxMay 13, 2026 Mar 23, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy,...Show more |
4Canonical ImagemagickOpensuse+1 more9Imagemagick LeapOpensuse+6 moreMay 13, 2026 Mar 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). |
4Canonical ImagemagickOpensuse+1 more8Imagemagick LeapOpensuse+5 moreMay 13, 2026 Mar 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption). |
4Canonical ImagemagickOpensuse+1 more9Imagemagick LeapOpensuse+6 moreMay 13, 2026 Mar 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The png coder in ImageMagick allows remote attackers to cause a denial of service (crash). |
4Canonical ImagemagickOpensuse+1 more10Imagemagick LeapLeap+7 moreMay 13, 2026 Mar 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption). |
4Canonical ImagemagickOpensuse+1 more10Imagemagick LeapOpensuse+7 moreMay 13, 2026 Mar 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. |
5Canonical ImagemagickOpensuse+2 more11Imagemagick LeapLeap+8 moreMay 13, 2026 Mar 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. |
5Canonical ImagemagickOpensuse+2 more11Imagemagick LeapLeap+8 moreMay 13, 2026 Mar 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file. |
5Canonical ImagemagickOpensuse+2 more10Imagemagick LeapOpensuse+7 moreMay 13, 2026 Mar 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file. |