CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Apr 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting addit...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Apr 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Apr 12, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Apr 12, 2017 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record siz...Show more |
2Debian Libsamplerate Project2Debian Linux LibsamplerateMay 13, 2026 Apr 11, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file. |
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator. |
Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafte...Show more |
2Debian Qemu2Debian Linux QemuMay 13, 2026 Apr 11, 2017 N/A· v4 6.5 MEDIUM· v3 4.7 MEDIUM· v2 Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly. |
Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client. |
2Debian Libtiff2Debian Linux LibtiffMay 13, 2026 Apr 11, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image. |
4Debian OpenbsdOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 29, 2026 Apr 11, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and...Show more |
3Debian OracleXmlsoft3Debian Linux Libxml2SolarisMay 13, 2026 Apr 11, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to se...Show more |
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors relat...Show more |
2Debian Opencv2Debian Linux OpencvMay 13, 2026 Apr 10, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
3Canonical DebianElfutils Project3Debian Linux ElfutilsUbuntu LinuxMay 13, 2026 Apr 9, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
6Apache CanonicalDebian+3 more197 Mode Transition Tool Agile Engineering Data ManagementAgile Plm+16 moreApr 21, 2026 Apr 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX p...Show more |