CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Google2Chrome Debian LinuxMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed v...Show more |
2Debian Google2Chrome Debian LinuxMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreMay 13, 2026 Oct 27, 2017 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by m...Show more |
5Debian NetappOpenbsd+2 more21Active Iq Unified Manager Cloud BackupClustered Data Ontap+18 moreMay 28, 2026 Oct 26, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. |
3Busybox CanonicalDebian3Busybox Debian LinuxUbuntu LinuxMay 13, 2026 Oct 24, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation. |
3Apache DebianRedhat11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreMay 13, 2026 Oct 24, 2017 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_t...Show more |
2Debian Irssi2Debian Linux IrssiMay 13, 2026 Oct 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message. |
2Debian Irssi2Debian Linux IrssiMay 13, 2026 Oct 22, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string. |
2Debian Irssi2Debian Linux IrssiMay 13, 2026 Oct 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468. |
2Debian Openslp2Debian Linux OpenslpMay 13, 2026 Oct 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package. |
2Apt Listbugs Project Debian2Apt Listbugs Debian LinuxMay 13, 2026 Oct 20, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors. |
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 19, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file. |
4Debian NetappOracle+1 more29Active Iq Unified Manager Cloud BackupDebian Linux+26 moreMay 13, 2026 Oct 19, 2017 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exp...Show more |
5Debian MariadbNetapp+2 more17Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+14 moreMay 13, 2026 Oct 19, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily exploitable vulnerability...Show more |