CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Feb 24, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Invalid Write and Integer Overflow." |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Feb 24, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Integer Overflow." |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Feb 24, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads." |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Feb 24, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h." |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Feb 24, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c." |
2Debian Ytnef Project2Debian Linux YtnefMay 13, 2026 Feb 24, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked." |
2Debian Quagga2Debian Linux QuaggaMay 13, 2026 Feb 22, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible wi...Show more |
2Debian Munin Monitoring2Debian Linux MuninMay 13, 2026 Feb 22, 2017 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user. |
3Debian FedoraprojectFlightgear3Debian Linux FedoraFlightgearMay 13, 2026 Feb 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script. |
2Debian Linux2Debian Linux Linux KernelMay 13, 2026 Feb 18, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cau...Show more |
2Canonical Debian2Debian Linux Ubuntu LinuxMay 13, 2026 Feb 17, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Feb 17, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not adv...Show more |
2Debian Simplesamlphp2Debian Linux SimplesamlphpMay 13, 2026 Feb 17, 2017 N/A· v4 6.3 MEDIUM· v3 4.0 MEDIUM· v2 The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging...Show more |
3Debian Icoutils ProjectRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Feb 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affects icotool. |
3Debian Icoutils ProjectRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Feb 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in...Show more |
3Debian Icoutils ProjectRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Feb 16, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked...Show more |
3Debian ImagemagickOpensuse3Debian Linux ImagemagickOpensuseMay 13, 2026 Feb 15, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure. |
3Debian Jasper ProjectRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreMay 13, 2026 Feb 15, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image. |
2Debian Imagemagick2Debian Linux ImagemagickMay 13, 2026 Feb 15, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. |
3Debian FedoraprojectJasper Project3Debian Linux FedoraJasperMay 13, 2026 Feb 15, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP im...Show more |