CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Libming2Debian Linux LibmingMay 13, 2026 Jun 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack. |
2Debian Libming2Debian Linux LibmingMay 13, 2026 Jun 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxMay 13, 2026 Jun 26, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack. |
3Canonical DebianLibtiff3Debian Linux LibtiffUbuntu LinuxMay 13, 2026 Jun 26, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bo...Show more |
2Debian Long Range Zip Project2Debian Linux Long Range ZipMay 13, 2026 Jun 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file. |
2Debian Long Range Zip Project2Debian Linux Long Range ZipMay 13, 2026 Jun 26, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file. |
2Debian Eclipse2Debian Linux MosquittoMay 13, 2026 Jun 25, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information. |
2Debian Freedesktop2Debian Linux PopplerMay 13, 2026 Jun 25, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to mis...Show more |
3Debian FreedesktopRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 22, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact v...Show more |
3Debian FreedesktopRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jun 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. |
2Debian Flatpak2Debian Linux FlatpakMay 13, 2026 Jun 21, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, w...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Jun 21, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c. |
6Apache AppleDebian+3 more13Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+10 moreMay 13, 2026 Jun 20, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence...Show more |
6Apache AppleDebian+3 more14Clustered Data Ontap Debian LinuxEnterprise Linux Desktop+11 moreMay 13, 2026 Jun 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. |
4Debian Libffi ProjectOracle+1 more6Debian Linux Enterprise LinuxEnterprise Virtualization Server+3 moreMay 13, 2026 Jun 19, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated th...Show more |
2Debian Exim2Debian Linux EximMay 13, 2026 Jun 19, 2017 N/A· v4 4.0 MEDIUM· v3 2.1 LOW· v2 Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version...Show more |
8Debian GnuMcafee+5 more20Cloud Magnum Orchestration Debian LinuxEnterprise Linux+17 moreMay 13, 2026 Jun 19, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hard...Show more |
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) vi...Show more |
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descri...Show more |
Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device. |