CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Nov 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or in...Show more |
3Debian RedhatTorproject8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreMay 13, 2026 Nov 4, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact vi...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB de...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 4, 2017 N/A· v4 6.6 MEDIUM· v3 7.2 HIGH· v2 The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified...Show more |
2Debian Yajl Ruby Project2Debian Linux Yajl RubyMay 13, 2026 Nov 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Nov 1, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code co...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Nov 1, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to t...Show more |
2Debian Haxx2Debian Linux LibcurlMay 13, 2026 Oct 31, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) t...Show more |
2Debian Redhat2Debian Linux LibvirtMay 13, 2026 Oct 31, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default. |
2Debian Quagga2Debian Linux QuaggaMay 13, 2026 Oct 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts cert...Show more |
2Bchunk Project Debian2Bchunk Debian LinuxMay 13, 2026 Oct 28, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file. |
2Bchunk Project Debian2Bchunk Debian LinuxMay 13, 2026 Oct 28, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file. |
2Bchunk Project Debian2Bchunk Debian LinuxMay 13, 2026 Oct 28, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file. |
The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's length, but doesn't check that the c...Show more |
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's lengt...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer. |