CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Unadf Project2Debian Linux UnadfMay 6, 2026 Oct 3, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file. |
2Debian Unadf Project2Debian Linux UnadfMay 6, 2026 Oct 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname. |
5C Ares C Ares ProjectCanonical+2 more5C Ares C AresDebian Linux+2 moreMay 6, 2026 Oct 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with a...Show more |
3Debian LibgdPhp3Debian Linux LibgdPhpMay 6, 2026 Sep 28, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer ov...Show more |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxMay 6, 2026 Sep 27, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxMay 6, 2026 Sep 27, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomple...Show more |
6Canonical DebianHp+3 more9Debian Linux Icewall Federation AgentIcewall Mcrp+6 moreMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr....Show more |
2Debian Inspircd2Debian Linux InspircdMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a cr...Show more |
4Debian EsNovell+1 more5Debian Linux Iperf3Leap+2 moreMay 6, 2026 Sep 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string,...Show more |
3Debian GoogleNodejs3Chrome Debian LinuxNode.jsMay 6, 2026 Sep 25, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code. |
2Apple Debian5Debian Linux Iphone OsMac Os X+2 moreMay 6, 2026 Sep 25, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. |
2Artifex Debian2Debian Linux MupdfMay 6, 2026 Sep 22, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array. |
4Debian FedoraprojectRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. |
2Charybdis Project Debian2Charybdis Debian LinuxMay 6, 2026 Sep 21, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter. |
2Apache Debian2Debian Linux JackrabbitMay 6, 2026 Sep 21, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.1...Show more |
2Debian Westes2Debian Linux FlexMay 6, 2026 Sep 21, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read...Show more |
2Debian Uclouvain2Debian Linux OpenjpegMay 6, 2026 Sep 21, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors. |
5Debian MariadbOracle+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreMay 6, 2026 Sep 20, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more |
4Canonical DebianLibarchive+1 more6Debian Linux LibarchiveLinux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left s...Show more |
4Canonical DebianLibarchive+1 more6Debian Linux LibarchiveLinux Enterprise Desktop+3 moreMay 6, 2026 Sep 20, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtre...Show more |