CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Linux4Linux Kernel Ubuntu CoreUbuntu Linux+1 moreMay 6, 2026 May 2, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 May 2, 2016 N/A· v4 5.1 MEDIUM· v3 1.9 LOW· v2 Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user...Show more |
3Canonical DebianOpenbsd5Debian Linux OpensshUbuntu Core+2 moreMay 6, 2026 May 1, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain priv...Show more |
3Canonical LinuxNovell9Linux Kernel Suse Linux Enterprise DesktopSuse Linux Enterprise Live Patching+6 moreMay 6, 2026 Apr 27, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on...Show more |
3Canonical LinuxNovell10Linux Kernel Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 moreMay 6, 2026 Apr 27, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of I...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corru...Show more |
3Canonical LinuxOpensuse3Leap Linux KernelUbuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by c...Show more |
3Canonical LinuxNovell10Linux Kernel Suse Linux Enterprise DebuginfoSuse Linux Enterprise Desktop+7 moreMay 6, 2026 Apr 27, 2016 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or do...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU. |
3Canonical LinuxNovell3Linux Kernel Suse Linux Enterprise Real Time ExtensionUbuntu LinuxMay 6, 2026 Apr 27, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraQemu+1 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU cras...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLibgd+3 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimizatio...Show more |
2Canonical Squid Cache2Squid Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses. |
3Canonical OracleSquid Cache3Linux SquidUbuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data. |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying t...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB s...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive info...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perfo...Show more |