CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-depe...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple integer overflows in the rb_ary_store function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22 allow context-dependent attackers to execute arbitrary code...Show more |
3Canonical DebianRuby Lang3Debian Linux RubyUbuntu LinuxApr 23, 2026 Jun 24, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allow context-dependent attackers...Show more |
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, wh...Show more |
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrat...Show more |
4Apache CanonicalFedoraproject+1 more7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 23, 2026 Jun 13, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP server...Show more |
2Canonical Openssl2Openssl Ubuntu LinuxApr 23, 2026 May 29, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer der...Show more |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxApr 23, 2026 May 29, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxApr 23, 2026 May 16, 2008 N/A· v4 N/A· v3 7.8 HIGH· v2 Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a S...Show more |
2Canonical Xiph.org2Libvorbis Ubuntu LinuxApr 23, 2026 May 16, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during exe...Show more |
3Canonical DebianOpenssl3Debian Linux OpensslUbuntu LinuxApr 23, 2026 May 13, 2008 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guess...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreApr 23, 2026 May 7, 2008 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which...Show more |
4Apple CanonicalFedoraproject+1 more5Fedora Mac Os XMac Os X Server+2 moreApr 23, 2026 May 5, 2008 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbit...Show more |
4Canonical DebianMysql+1 more4Debian Linux MysqlMysql+1 moreApr 23, 2026 May 5, 2008 N/A· v4 N/A· v3 4.6 MEDIUM· v2 MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux FedoraLinux Enterprise Desktop+5 moreApr 23, 2026 May 2, 2008 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less...Show more |
3Canonical DebianPython3Debian Linux PythonUbuntu LinuxApr 23, 2026 Apr 10, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffe...Show more |
7Apple CanonicalDebian+4 more11Debian Linux FedoraKerberos 5+8 moreApr 23, 2026 Mar 19, 2008 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraKerberos 5+1 moreApr 23, 2026 Mar 19, 2008 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that...Show more |