CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apple CanonicalDebian+3 more6Debian Linux FedoraMac Os X+3 moreApr 23, 2026 Jul 31, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via ve...Show more |
5Canonical DebianMozilla+2 more9Debian Linux FirefoxLinux Enterprise+6 moreApr 23, 2026 Jul 30, 2009 N/A· v4 5.9 MEDIUM· v3 6.8 MEDIUM· v2 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Jul 16, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU co...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 5, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 Jul 1, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a den...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 23, 2026 Jun 25, 2009 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access con...Show more |
3Apple CanonicalOpensuse4Iphone Os OpensuseSafari+1 moreApr 23, 2026 Jun 10, 2009 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote atta...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxLinux Enterprise+4 moreApr 23, 2026 Jun 9, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and da...Show more |
5Canonical DebianLinux+2 more7Debian Linux Linux EnterpriseLinux Enterprise Desktop+4 moreApr 23, 2026 Jun 8, 2009 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a den...Show more |
2Apache Canonical3Apr Util Http ServerUbuntu LinuxApr 23, 2026 Jun 8, 2009 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via cr...Show more |
7Apache AppleCanonical+4 more8Apr Util Debian LinuxFedora+5 moreApr 23, 2026 Jun 8, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of ser...Show more |
3Canonical OpensslRedhat3Openssl OpensslUbuntu LinuxApr 23, 2026 Jun 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS h...Show more |
3Canonical OpensslRedhat3Openssl OpensslUbuntu LinuxApr 23, 2026 Jun 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 May 28, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malforme...Show more |
2Canonical Openssl2Openssl Ubuntu LinuxApr 23, 2026 May 19, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS recor...Show more |
5Canonical DebianLinux+2 more5Debian Linux EsxLinux Kernel+2 moreApr 23, 2026 May 14, 2009 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which a...Show more |
2Apache Canonical2Http Server Ubuntu LinuxApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Debuginfo+5 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments. |
7Canonical DebianFedoraproject+4 more9Ctpview Debian LinuxFedora+6 moreApr 23, 2026 Apr 17, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. |