CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apport Project Canonical2Apport Ubuntu LinuxMay 6, 2026 Dec 17, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary P...Show more |
3Canonical DebianGnupg4Debian Linux GnupgLibgcrypt+1 moreMay 6, 2026 Dec 13, 2016 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveragin...Show more |
3Canonical DjangoprojectFedoraproject3Django FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host heade...Show more |
3Canonical DjangoprojectFedoraproject3Django FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attack...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Dec 8, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Nov 28, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does not properly check permissions for file creation in the upper filesystem directory, which allows local...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Nov 16, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of t...Show more |
2Canonical Xmlsoft2Libxml2 Ubuntu LinuxMay 6, 2026 Nov 16, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, which makes it easier...Show more |
7Canonical DebianFedoraproject+4 more18Cloud Backup Debian LinuxEnterprise Linux+15 moreApr 21, 2026 Nov 10, 2016 N/A· v4 7.0 HIGH· v3 7.2 HIGH· v2 Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Oct 16, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of servic...Show more |
2Canonical Systemd Project2Systemd Ubuntu LinuxMay 6, 2026 Oct 13, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure and PID 1 hang) via a zero-length message received over a notify socket. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Oct 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandl...Show more |
3Canonical DebianDjangoproject3Debian Linux DjangoUbuntu LinuxMay 6, 2026 Oct 3, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies. |
3Canonical GnomeOpensuse4Gdk Pixbuf LeapOpensuse+1 moreMay 6, 2026 Oct 3, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file. |
2Canonical Clamav2Clamav Ubuntu LinuxMay 6, 2026 Oct 3, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file. |
2Canonical Clamav2Clamav Ubuntu LinuxMay 6, 2026 Oct 3, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable. |
5C Ares C Ares ProjectCanonical+2 more5C Ares C AresDebian Linux+2 moreMay 6, 2026 Oct 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with a...Show more |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxMay 6, 2026 Sep 27, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxMay 6, 2026 Sep 27, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomple...Show more |
6Canonical DebianHp+3 more9Debian Linux Icewall Federation AgentIcewall Mcrp+6 moreMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr....Show more |