CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary c...Show more |
2Debian Kitfox2Debian Linux Svg SalamanderMay 13, 2026 Mar 16, 2017 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file. |
2Artifex Debian2Debian Linux MupdfMay 13, 2026 Mar 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. |
2Artifex Debian2Debian Linux MupdfMay 13, 2026 Mar 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. |
2Debian Osgeo2Debian Linux MapserverMay 13, 2026 Mar 15, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors inv...Show more |
7Debian FedoraprojectJqueryui+4 more13Application Express Business IntelligenceDebian Linux+10 moreMay 13, 2026 Mar 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. |
2Debian Qemu2Debian Linux QemuMay 13, 2026 Mar 15, 2017 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a lar...Show more |
2Debian Qemu2Debian Linux QemuMay 13, 2026 Mar 15, 2017 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug opera...Show more |
2Debian Qemu2Debian Linux QemuMay 13, 2026 Mar 15, 2017 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operati...Show more |
2Debian Libevent Project2Debian Linux LibeventMay 13, 2026 Mar 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname. |
3Debian Libevent ProjectMozilla4Debian Linux FirefoxLibevent+1 moreMay 13, 2026 Mar 15, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in b...Show more |
2Debian Libevent Project2Debian Linux LibeventMay 13, 2026 Mar 15, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read. |
2Debian Qemu2Debian Linux QemuMay 13, 2026 Mar 15, 2017 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unp...Show more |
2Artifex Debian2Debian Linux MupdfMay 13, 2026 Mar 15, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image. |
4Debian OpensuseOpensuse Project+1 more4Debian Linux LeapLeap+1 moreMay 13, 2026 Mar 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Mar 12, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-inc...Show more |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Mar 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef. |