CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper...Show more |
2Debian Exim2Debian Linux EximMay 13, 2026 Nov 25, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands. |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Nov 24, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system...Show more |
2Debian Neutrinolabs2Debian Linux XrdpMay 13, 2026 Nov 23, 2017 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow an...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Nov 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables wh...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Nov 22, 2017 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or dis...Show more |
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell...Show more |
2Debian Openstack3Debian Linux SwauthSwiftMay 13, 2026 Nov 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth mid...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Nov 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c...Show more |
2Debian Libxls Project2Debian Linux LibxlsMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can...Show more |
2Debian Libxls Project2Debian Linux LibxlsMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send...Show more |
3Apache DebianRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Nov 20, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker b...Show more |
2Apache Debian2Debian Linux OpenofficeMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and appli...Show more |
2Apache Debian2Debian Linux OpenofficeMay 13, 2026 Nov 20, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potent...Show more |
2Debian Xfig Project2Debian Linux XfigMay 13, 2026 Nov 20, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font valu...Show more |
5Busybox CanonicalDebian+2 more6Busybox Debian LinuxEsxi+3 moreMay 13, 2026 Nov 20, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 13, 2026 Nov 17, 2017 N/A· v4 10.0 CRITICAL· v3 6.4 MEDIUM· v2 hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. |
2Debian Teluu2Debian Linux PjsipMay 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing u...Show more |
2Debian Optipng Project2Debian Linux OptipngMay 13, 2026 Nov 17, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service. |
2Debian Python2Debian Linux PythonMay 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution) |