CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian LibgdOpensuse3Debian Linux LeapLibgdMay 6, 2026 Aug 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file. |
4Debian LibgdOpensuse+1 more4Debian Linux LeapLibgd+1 moreMay 6, 2026 Aug 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory cons...Show more |
3Debian LibgdOpensuse3Debian Linux LeapLibgdMay 6, 2026 Aug 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image. |
3Debian LibgdOpensuse3Debian Linux LeapLibgdMay 6, 2026 Aug 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file. |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraLeap+3 moreMay 6, 2026 Aug 10, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors. |
3Debian HaxxOpensuse3Debian Linux LeapLibcurlMay 6, 2026 Aug 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously c...Show more |
3Debian HaxxOpensuse3Debian Linux LeapLibcurlMay 6, 2026 Aug 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session. |
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file. |
2Debian Wordpress2Debian Linux WordpressMay 6, 2026 Aug 7, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address. |
4Canonical DebianLibgd+1 more4Debian Linux LeapLibgd+1 moreMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid col...Show more |
4Debian OpensusePhp+1 more7Debian Linux LeapLinux Enterprise Debuginfo+4 moreMay 6, 2026 Aug 7, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (applic...Show more |
3Debian OpensusePhp4Debian Linux LeapOpensuse+1 moreMay 6, 2026 Aug 7, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or ca...Show more |
3Debian OpensusePhp4Debian Linux LeapOpensuse+1 moreMay 6, 2026 Aug 7, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified...Show more |
5Debian FedoraprojectFreebsd+2 more6Debian Linux Enterprise LinuxFedora+3 moreMay 6, 2026 Aug 7, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more |
3Debian LibgdOpensuse3Debian Linux LeapLibgdMay 6, 2026 Aug 7, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial o...Show more |
2Debian Linux2Debian Linux Linux KernelMay 6, 2026 Aug 6, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer...Show more |
2Debian Google2Android Debian LinuxMay 6, 2026 Aug 5, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denia...Show more |
2Debian Djangoproject2Debian Linux DjangoMay 6, 2026 Aug 5, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10r...Show more |
5Canonical DebianOracle+2 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreMay 6, 2026 Aug 2, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraPerl+2 moreMay 6, 2026 Aug 2, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working...Show more |