CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Nov 17, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/di...Show more |
7Canonical DebianFedoraproject+4 more18Cloud Backup Debian LinuxEnterprise Linux+15 moreApr 21, 2026 Nov 10, 2016 N/A· v4 7.0 HIGH· v3 7.2 HIGH· v2 Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more |
4Debian OpensuseQemu+1 more5Debian Linux LeapOpenstack+2 moreMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit th...Show more |
4Debian OpensuseQemu+1 more5Debian Linux LeapOpenstack+2 moreMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for...Show more |
4Debian OpensuseQemu+1 more5Debian Linux LeapOpenstack+2 moreMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving...Show more |
3Debian OpensuseQemu3Debian Linux LeapQemuMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The rc4030_write function in hw/dma/rc4030.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via a large interval timer reload...Show more |
3Debian OpensuseQemu3Debian Linux LeapQemuMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The v9fs_iov_vunmarshal function in fsdev/9p-iov-marshal.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) by sending an em...Show more |
3Debian OpensuseQemu3Debian Linux LeapQemuMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 Memory leak in the v9fs_read function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors related to an I/O read operation. |
4Debian OpensuseQemu+1 more5Debian Linux LeapOpenstack+2 moreMay 6, 2026 Nov 4, 2016 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the n...Show more |
2Debian Python2Debian Linux PillowMay 6, 2026 Nov 4, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. |
2Debian Python2Debian Linux PillowMay 6, 2026 Nov 4, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c compo...Show more |
4Debian IscNetapp+1 more11Bind Data Ontap EdgeDebian Linux+8 moreMay 6, 2026 Nov 2, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer sectio...Show more |
3Debian MariadbOracle3Debian Linux MariadbMysqlMay 6, 2026 Oct 25, 2016 N/A· v4 4.4 MEDIUM· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxMay 6, 2026 Oct 10, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandl...Show more |
2Debian Libav2Debian Linux LibavMay 6, 2026 Oct 7, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file. |
The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) trans...Show more |
The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of s...Show more |
Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet. |
2Dbd Mysql Project Debian2Dbd Mysql Debian LinuxMay 6, 2026 Oct 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message. |
3Canonical DebianDjangoproject3Debian Linux DjangoUbuntu LinuxMay 6, 2026 Oct 3, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies. |