CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. |
3Canonical DebianLibarchive3Debian Linux LibarchiveUbuntu LinuxMay 6, 2026 Sep 20, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereferenc...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Sep 9, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form. |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (application crash) via a craf...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (in...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 6, 2026 Sep 9, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overl...Show more |
3Cracklib Project DebianOpensuse3Cracklib Debian LinuxLeapMay 6, 2026 Sep 7, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffe...Show more |
2Debian Rubyonrails3Debian Linux RailsRuby On RailsMay 6, 2026 Sep 7, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declar...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 7, 2016 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via uns...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bound...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read ho...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Sep 2, 2016 N/A· v4 6.0 MEDIUM· v3 1.9 LOW· v2 QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vectors related to the (...Show more |
fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service...Show more |
3Collectd DebianFedoraproject3Collectd Debian LinuxFedoraMay 6, 2026 Aug 19, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code vi...Show more |
2Dbd Mysql Project Debian2Dbd Mysql Debian LinuxMay 6, 2026 Aug 19, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login. |
2Dbd Mysql Project Debian2Dbd Mysql Debian LinuxMay 6, 2026 Aug 19, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFontconfig+1 moreMay 6, 2026 Aug 13, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file. |