CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jul 18, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt. |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jul 18, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Frame Control parameter values. |
3Debian FreeradiusRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jul 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service. |
3Canonical DebianImagemagick3Debian Linux ImagemagickUbuntu LinuxMay 13, 2026 Jul 17, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144. |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Jul 17, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google...Show more |
6Apache AppleDebian+3 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Server+12 moreMay 13, 2026 Jul 13, 2017 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_d...Show more |
5Apple DebianFreebsd+2 more6Debian Linux FreebsdHeimdal+3 moreMay 13, 2026 Jul 13, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_tick...Show more |
2Debian Rack Cors Project2Debian Linux Rack CorsMay 13, 2026 Jul 13, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the...Show more |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Jul 11, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of ser...Show more |
2Debian Graphicsmagick2Debian Linux GraphicsmagickMay 13, 2026 Jul 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c. |
2Debian Phpldapadmin Project2Debian Linux PhpldapadminMay 13, 2026 Jul 8, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter. |
2Debian Knot Dns2Debian Linux Knot DnsMay 13, 2026 Jul 8, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL res...Show more |
The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging fa...Show more |
2Debian Jython Project2Debian Linux JythonMay 13, 2026 Jul 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. |
2Debian Puppet2Debian Linux PuppetMay 13, 2026 Jul 5, 2017 N/A· v4 8.2 HIGH· v3 6.0 MEDIUM· v2 Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, w...Show more |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Jul 4, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-i...Show more |
2Debian Xml Libxml Project2Debian Linux Xml LibxmlMay 13, 2026 Jun 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call. |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Jun 28, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of servic...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Jun 28, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrar...Show more |
2Debian Ffmpeg2Debian Linux FfmpegMay 13, 2026 Jun 28, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a de...Show more |