CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. |
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. |
2Debian Sound Exchange Project2Debian Linux Sound ExchangeMay 13, 2026 Oct 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file. |
4Apache CanonicalDebian+1 more4Debian Linux Jboss Enterprise Application PlatformSolr+1 moreMay 13, 2026 Oct 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch,...Show more |
3Canonical DebianLibsdl3Debian Linux Simple Directmedia LayerUbuntu LinuxMay 13, 2026 Oct 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a...Show more |
2Debian Libsdl2Debian Linux Sdl ImageMay 13, 2026 Oct 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code executio...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Oct 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects c...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Oct 11, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length. |
2Apache Debian2Debian Linux ZookeeperMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooK...Show more |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large...Show more |
2Debian X.org2Debian Linux X ServerMay 13, 2026 Oct 10, 2017 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other...Show more |
3Debian GolangRedhat7Debian Linux Developer ToolsEnterprise Linux Eus+4 moreMay 13, 2026 Oct 5, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2...Show more |
3Debian MercurialRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Oct 5, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks. |
3Debian MercurialRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Oct 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository |
3Debian LinuxRedhat9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreMay 13, 2026 Oct 5, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Oct 4, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c. |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Oct 4, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield...Show more |
12Arista ArubanetworksCanonical+9 more21Arubaos Debian LinuxDiskstation Manager+18 moreMay 13, 2026 Oct 4, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. |
6Apache CanonicalDebian+3 more58Active Iq Unified Manager Agile PlmCommunications Instant Messaging Server+55 moreApr 21, 2026 Oct 4, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to fal...Show more |