CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 29, 2026 Jul 29, 2011 N/A· v4 N/A· v3 2.6 LOW· v2 Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 29, 2026 Jul 29, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attackers to hijack the authentication of administrators for requests that (1...Show more |
2Canonical Debian2Advanced Package Tool Ubuntu LinuxApr 29, 2026 Jul 27, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message. |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Jul 18, 2011 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently ca...Show more |
3Canonical LinuxVmware3Esx Linux KernelUbuntu LinuxApr 29, 2026 Jul 18, 2011 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADM...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cau...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function but not the png_set_expand function, all...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibpng+1 moreApr 29, 2026 Jul 17, 2011 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a c...Show more |
5Apple CanonicalDebian+2 more5Debian Linux FedoraLibcurl+2 moreApr 29, 2026 Jul 7, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers...Show more |
5Apache AppleCanonical+2 more5Debian Linux FedoraMac Os X+2 moreApr 29, 2026 Jun 6, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of se...Show more |
5Apache AppleCanonical+2 more5Debian Linux FedoraMac Os X+2 moreApr 29, 2026 Jun 6, 2011 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a b...Show more |
2Canonical Eucalyptus2Eucalyptus Ubuntu LinuxApr 29, 2026 Jun 2, 2011 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to...Show more |
3Canonical LinuxRedhat8Enterprise Linux Enterprise Linux AusEnterprise Linux Desktop+5 moreApr 29, 2026 May 3, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system ca...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Apr 10, 2011 N/A· v4 N/A· v3 2.1 LOW· v2 The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which al...Show more |
3Canonical DebianIsc3Debian Linux DhcpUbuntu LinuxApr 29, 2026 Apr 8, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained fro...Show more |
2Canonical Debian3Debian Linux Tex CommonUbuntu LinuxApr 29, 2026 Mar 25, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating...Show more |
3Canonical LinuxRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Mar 15, 2011 N/A· v4 N/A· v3 5.7 MEDIUM· v2 Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLinux Enterprise Server+3 moreApr 29, 2026 Mar 2, 2011 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT com...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Mar 1, 2011 N/A· v4 N/A· v3 7.2 HIGH· v2 Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partiti...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxApr 29, 2026 Mar 1, 2011 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The ldm_parse_vmdb function in fs/partitions/ldm.c in the Linux kernel before 2.6.38-rc6-git6 does not validate the VBLK size value in the VMDB structure in an LDM partition table, which allows local users to cause a den...Show more |