CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical ImagemagickOpensuse+1 more8Imagemagick LeapOpensuse+5 moreMay 13, 2026 Mar 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. |
4Canonical ImagemagickOpensuse+1 more9Imagemagick LeapOpensuse+6 moreMay 13, 2026 Mar 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. |
4Canonical ImagemagickOpensuse+1 more8Imagemagick LeapOpensuse+5 moreMay 13, 2026 Mar 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions." |
4Canonical ImagemagickOpensuse+1 more7Imagemagick LeapLinux Enterprise Server+4 moreMay 13, 2026 Mar 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image." |
6Canonical ImagemagickNovell+3 more11Imagemagick LeapLeap+8 moreMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. |
3Apng2gif Project CanonicalDebian3Apng2gif Debian LinuxUbuntu LinuxMay 13, 2026 Mar 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable. |
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Feb 24, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protect...Show more |
2Canonical Muscle2Pcsc Lite Ubuntu LinuxMay 13, 2026 Feb 23, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext...Show more |
2Canonical Debian2Debian Linux Ubuntu LinuxMay 13, 2026 Feb 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable...Show more |
4Canonical DebianLibjpeg Turbo+1 more4Debian Linux Enterprise LinuxLibjpeg Turbo+1 moreMay 13, 2026 Feb 13, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file. |
2Canonical Click Project2Click Ubuntu LinuxMay 13, 2026 Feb 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted packag...Show more |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxMay 13, 2026 Feb 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing. |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxMay 13, 2026 Feb 9, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write. |
6Canonical DebianLittlecms+3 more19Active Iq Unified Manager Debian LinuxE Series Santricity Management+16 moreMay 13, 2026 Feb 3, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bo...Show more |
3Canonical DebianExim3Debian Linux EximUbuntu LinuxMay 13, 2026 Feb 1, 2017 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages. |
3Canonical DebianMoinmo3Debian Linux MoinmoinUbuntu LinuxMay 13, 2026 Jan 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
8Canonical DebianFedoraproject+5 more10Clustered Data Ontap Debian LinuxFedora+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. |
5Canonical FreebsdNetapp+2 more7Clustered Data Ontap FreebsdNtp+4 moreMay 13, 2026 Jan 30, 2017 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. |
5Canonical DebianMariadb+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 13, 2026 Jan 27, 2017 N/A· v4 4.7 MEDIUM· v3 1.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vul...Show more |