CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache DebianNetapp+1 more11Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+8 moreMay 13, 2026 Jul 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security conc...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Jul 27, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input. |
2Artifex Debian2Debian Linux GhostscriptMay 13, 2026 Jul 26, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impac...Show more |
2Artifex Debian2Debian Linux Ghostscript GhostxpsMay 13, 2026 Jul 26, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other im...Show more |
2Artifex Debian2Debian Linux Ghostscript GhostxpsMay 13, 2026 Jul 26, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified...Show more |
2Artifex Debian2Debian Linux Ghostscript GhostxpsMay 13, 2026 Jul 26, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other im...Show more |
2Artifex Debian2Debian Linux Ghostscript GhostxpsMay 13, 2026 Jul 26, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via a craf...Show more |
2Artifex Debian2Debian Linux GhostscriptMay 13, 2026 Jul 26, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other im...Show more |
3Debian Libexpat ProjectPython3Debian Linux LibexpatPythonMay 13, 2026 Jul 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop using a malformed external entity definition from an external DTD. |
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string. |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 13, 2026 Jul 25, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC...Show more |
5Debian NetappNtp+2 more13Clustered Data Ontap Data OntapDebian Linux+10 moreMay 13, 2026 Jul 24, 2017 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send...Show more |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxMay 13, 2026 Jul 24, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input. |
2Debian Resiprocate2Debian Linux ResiprocateMay 13, 2026 Jul 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by triggering many media connections. |
7Canonical DebianFedoraproject+4 more20Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+17 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more |
10Canonical DebianFedoraproject+7 more18Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+15 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a craft...Show more |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation. |
6Canonical DebianFedoraproject+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+10 moreMay 13, 2026 Jul 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. |
2Debian Imagemagick2Debian Linux ImagemagickMay 13, 2026 Jul 19, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jul 18, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type. |