CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Openvpn2Debian Linux OpenvpnMay 13, 2026 Oct 4, 2017 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Oct 3, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accou...Show more |
6Canonical DebianGoogle+3 more8Android Debian LinuxDnsmasq+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS req...Show more |
4Canonical DebianRedhat+1 more6Debian Linux DnsmasqEnterprise Linux Desktop+3 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creat...Show more |
5Canonical DebianNovell+2 more7Debian Linux DnsmasqEnterprise Linux Desktop+4 moreMay 13, 2026 Oct 3, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests. |
5Canonical DebianOpensuse+2 more7Debian Linux DnsmasqEnterprise Linux Desktop+4 moreMay 13, 2026 Oct 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request. |
4Canonical DebianRedhat+1 more6Debian Linux DnsmasqEnterprise Linux Desktop+3 moreMay 13, 2026 Oct 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request. |
6Canonical DebianFedoraproject+3 more8Debian Linux DnsmasqEnterprise Linux Desktop+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xff...Show more |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Oct 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of servic...Show more |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Oct 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a de...Show more |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Oct 2, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service...Show more |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Sep 30, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Sep 30, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document. |
Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Sep 29, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Sep 29, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Sep 29, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. |
2Botan Project Debian2Botan Debian LinuxMay 13, 2026 Sep 26, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Sep 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via...Show more |
2Debian Jsoup2Debian Linux JsoupMay 13, 2026 Sep 25, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3. |