CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mini Xml Project2Debian Linux Mini XmlMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. |
2Debian Mini Xml Project2Debian Linux Mini XmlMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. |
4Debian GraphicsmagickOpensuse+1 more7Debian Linux GraphicsmagickLeap+4 moreMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in code...Show more |
4Debian GraphicsmagickOpensuse+1 more7Debian Linux GraphicsmagickLeap+4 moreMay 13, 2026 Feb 3, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in m...Show more |
3Canonical DebianExim3Debian Linux EximUbuntu LinuxMay 13, 2026 Feb 1, 2017 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages. |
3Canonical DebianMoinmo3Debian Linux MoinmoinUbuntu LinuxMay 13, 2026 Jan 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2Debian Ruby Lang2Debian Linux OpensslMay 13, 2026 Jan 30, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mecha...Show more |
2Cryptopp Debian2Crypto++ Debian LinuxMay 13, 2026 Jan 30, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 object. If there is not enough content octe...Show more |
7Debian FreebsdNetapp+4 more17Clustered Data Ontap Communications User Data RepositoryData Ontap+14 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. |
8Canonical DebianFedoraproject+5 more10Clustered Data Ontap Debian LinuxFedora+7 moreMay 13, 2026 Jan 30, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Jan 30, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via a crafted e...Show more |
3Debian OracleWordpress3Data Integrator Debian LinuxWordpressMay 13, 2026 Jan 30, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that...Show more |
2Debian Wordpress2Debian Linux WordpressMay 13, 2026 Jan 30, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access res...Show more |
3Debian RedhatTcpdump8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jan 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print(). |
3Debian RedhatTcpdump8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jan 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print(). |
3Debian RedhatTcpdump8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jan 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). |
3Debian RedhatTcpdump8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Jan 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Jan 27, 2017 N/A· v4 4.0 MEDIUM· v3 1.0 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exp...Show more |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Jan 27, 2017 N/A· v4 4.0 MEDIUM· v3 1.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerabil...Show more |
5Canonical DebianMariadb+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 13, 2026 Jan 27, 2017 N/A· v4 4.7 MEDIUM· v3 1.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vul...Show more |