CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoi...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-se...Show more |
2Canonical Samba2Samba Ubuntu LinuxMay 6, 2026 Apr 25, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (a...Show more |
3Canonical Hexchat ProjectXchat4Hexchat Ubuntu LinuxXchat+1 moreMay 6, 2026 Apr 21, 2016 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle atta...Show more |
8Apache CanonicalDebian+5 more38Cassandra Debian LinuxE Series Santricity Management Plug Ins+35 moreApr 22, 2026 Apr 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
6Canonical DebianMariadb+3 more10Debian Linux LeapLinux Enterprise Desktop+7 moreMay 6, 2026 Apr 21, 2016 N/A· v4 4.1 MEDIUM· v3 1.7 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB. |
3Canonical OracleRedhat3Enterprise Linux MysqlUbuntu LinuxMay 6, 2026 Apr 21, 2016 N/A· v4 5.5 MEDIUM· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption. |
3Canonical OracleRedhat3Enterprise Linux MysqlUbuntu LinuxMay 6, 2026 Apr 21, 2016 N/A· v4 4.7 MEDIUM· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options. |
7Canonical DebianMariadb+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreMay 6, 2026 Apr 21, 2016 N/A· v4 4.7 MEDIUM· v3 4.3 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated. |
2Canonical Optipng Project2Optipng Ubuntu LinuxMay 6, 2026 Apr 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file. |
2Canonical Optipng Project2Optipng Ubuntu LinuxMay 6, 2026 Apr 20, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file. |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more |
3Canonical DebianGnupg3Debian Linux LibgcryptUbuntu LinuxMay 6, 2026 Apr 19, 2016 N/A· v4 2.0 LOW· v3 1.9 LOW· v2 Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanation...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux OpensuseUbuntu Linux+1 moreMay 6, 2026 Apr 19, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file. |
5Canonical FedoraprojectGnu+2 more9Fedora GlibcLinux Enterprise Debuginfo+6 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more |
2Canonical Videolan2Ubuntu Linux Vlc Media PlayerMay 6, 2026 Apr 18, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across E...Show more |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
5Canonical DebianGoogle+2 more5Chrome Debian LinuxLeap+2 moreMay 6, 2026 Apr 18, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecifie...Show more |